Skip to main content

AGENTFORCE-26.1: Record Access by Caller-Supplied ID Without Sharing (IDOR)

๐Ÿ”ด High ยท Broken Access Control

Detects Apex/Visualforce/LWC controllers and agent actions that read records by an id the caller or the AI supplies without sharing enforcement, USER_MODE or an ownership check (insecure direct object reference), and id inputs concatenated into Named Credential callout paths.

Detailsโ€‹

FieldValue
Rule IDAGENTFORCE-26.1
SeverityHigh
CategoryBroken Access Control
ComplianceSOC2_CC6, HIPAA

Remediationโ€‹

Declare the class 'with sharing' (or query WITH USER_MODE / AccessLevel.USER_MODE) so the platform only returns records the running user can see, and for guest or agent entry points also verify ownership (e.g. the record belongs to the session's contact). For callouts, validate that the id belongs to a record the user can access before building the URL.

See Alsoโ€‹