View online: https://www.drupal.org/sa-contrib-2026-063 Project: Salesforce Suite [1] Date: 2026-June-24 Security risk: *Moderately critical* 11 ∕ 25 AC:Complex/A:User/CI:Some/II:Some/E:Theoretical/TD:Uncommon [2] Vulnerability: Cross-site request forgery Affected versions: <5.1.3 CVE IDs: CVE-2026-13243 Description: The Salesforce Suite of modules integrates Drupal with Salesforce. The Salesforce module does not properly validate the OAuth handshake during interactive authentication, allowing an attacker to hijack the authorization token and bind the site to an attacker's Salesforce account. This vulnerability is mitigated by the fact that salesforce_oauth submodule must be enabled, and a salesforce_oauth authorization profile active and in use. The submodule salesforce_oauth is deprecated, and salesforce_jwt has been the recommended authentication plugin for several years. Sites with salesforce_oauth uninstalled, or sites relying exclusively on salesforce_jwt (JWT or JWT Gov Cloud) for authentication are not impacted. Submodule salesforce_oauth has been removed in branch 6.0.x, so >= 6.0.x versions are not affected by this vulnerability. Solution: *Recommended solution:* * Update to Salesforce Suite version 5.1.3 [3] * Uninstall salesforce_oauth module *Alternative solution*, if you must continue to use salesforce_oauth module: * Update to Salesforce Suite version 5.1.3 [4] * Revoke existing oauth provider tokens * Re-authenticate all existing oauth providers Reported By: * Muhammedali Aliyev (swordmein) [5] Fixed By: * Aaron Bauman (aaronbauman) [6] Coordinated By: * Neil Drumm (drumm) [7] of the Drupal Security Team * Juraj Nemec (poker10) [8] of the Drupal Security Team * Pierre Rudloff (prudloff) [9] of the Drupal Security Team Security issue: https://git.drupalcode.org/security/185127-salesforce-security/-/work_items/... [10] ------------------------------------------------------------------------------ Contribution record [11] [1] https://www.drupal.org/project/salesforce [2] https://www.drupal.org/security-team/risk-levels [3] https://www.drupal.org/project/salesforce/releases/5.1.3 [4] https://www.drupal.org/project/salesforce/releases/5.1.3 [5] https://www.drupal.org/u/swordmein [6] https://www.drupal.org/u/aaronbauman [7] https://www.drupal.org/u/drumm [8] https://www.drupal.org/u/poker10 [9] https://www.drupal.org/u/prudloff [10] https://git.drupalcode.org/security/185127-salesforce-security/-/work_items/... [11] https://new.drupal.org/contribution-record?source_link=https%3A//www.drupal....