Google’s Mandiant released AuraInspector, an open-source command-line tool designed to identify access-control misconfigurations in Salesforce Experience Cloud deployments that use the Aura framework (part of Salesforce’s Lightning Experience). The tool targets the Aura endpoint, a commonly attacked surface in Experience Cloud applications, where complex, multi-layered Salesforce permission and object-sharing configurations can lead to unintended data exposure to external or even unauthenticated users.
AuraInspector automates external-style testing of Aura endpoints to surface excessive data access paths and provide remediation guidance. Reported capabilities include automatic Aura endpoint discovery, object/record access scanning, exposed record list discovery (including URLs), checks for self-registration enablement, and techniques to retrieve larger datasets (e.g., a GraphQL-based method to fetch more than 2,000 records and “action bulking” to send multiple actions in one request). It inspects responses from Aura methods such as getItems and getConfigData to detect overexposure of sensitive records (e.g., payment data, identity documents, health information) and is available on GitHub in a read-only mode intended to avoid making changes to target environments.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
In conjunction with AuraInspector, Mandiant revealed a previously undocumented technique using Salesforce's GraphQL Aura controller to bypass the standard 2,000-record retrieval limit. The method enables more complete impact assessment when misconfigurations allow unauthorized access to Salesforce data.
Google and Mandiant released AuraInspector, an open-source, read-only command-line tool to audit Salesforce Experience Cloud applications for Aura access-control misconfigurations and unintended data exposure. The tool was made freely available on GitHub to help defenders assess Aura endpoint exposure at scale.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcecybersecuritynews.com
Open sourcehelpnetsecurity.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.