Skip to main content

AGENTFORCE-25.6: Apex without sharing Bypass

๐Ÿ”ด High ยท Broken Access Control

Detects Apex classes declared without sharing, which ignore record-level sharing rules and can expose privileged data to callers.

Detailsโ€‹

FieldValue
Rule IDAGENTFORCE-25.6
SeverityHigh
CategoryBroken Access Control
ComplianceSOC2_CC6, HIPAA

Remediationโ€‹

Use with sharing (or inherited sharing) unless a documented privileged operation requires without sharing, and gate that path behind explicit CRUD/FLS checks.

See Alsoโ€‹