HackerOne Disclosed Reports - 2026-09-06

0 Replies, 1 Views

Logo
High
resolved

PII Exposure of Credit Applications and Social Security Numbers equifax-6070.my.salesforce-sites.com (Salesforce guest user)


Bug reported by David Crees was disclosed at September 6, 2026, 10:03 am   |   Improper Authentication - Generic

A Salesforce community portal belonging to Equifax was found to be leaking tens of thousands of credit reports and other sensitive financial information. The portal's Salesforce guest user profile and sharing settings granted unauthenticated access to multiple objects, including Contact, Online_Credit_Application__c, and related financial data. This exposure allowed an anonymous user to read a large number of records containing sensitive personally identifiable information.


[Image: e72398fe92beda2aa80d0329e8b9f4febece7568.gif]



Users browsing this thread: 1 Guest(s)