AGENTFORCE-26.1: Record Access by Caller-Supplied ID Without Sharing (IDOR)
๐ด High ยท Broken Access Control
Detects Apex/Visualforce/LWC controllers and agent actions that read records by an id the caller or the AI supplies without sharing enforcement, USER_MODE or an ownership check (insecure direct object reference), and id inputs concatenated into Named Credential callout paths.
Detailsโ
| Field | Value |
|---|---|
| Rule ID | AGENTFORCE-26.1 |
| Severity | High |
| Category | Broken Access Control |
| Compliance | SOC2_CC6, HIPAA |
Remediationโ
Declare the class 'with sharing' (or query WITH USER_MODE / AccessLevel.USER_MODE) so the platform only returns records the running user can see, and for guest or agent entry points also verify ownership (e.g. the record belongs to the session's contact). For callouts, validate that the id belongs to a record the user can access before building the URL.