AGENTFORCE-25.6: Apex without sharing Bypass
๐ด High ยท Broken Access Control
Detects Apex classes declared without sharing, which ignore record-level sharing rules and can expose privileged data to callers.
Detailsโ
| Field | Value |
|---|---|
| Rule ID | AGENTFORCE-25.6 |
| Severity | High |
| Category | Broken Access Control |
| Compliance | SOC2_CC6, HIPAA |
Remediationโ
Use with sharing (or inherited sharing) unless a documented privileged operation requires without sharing, and gate that path behind explicit CRUD/FLS checks.