Skip to main content

AGENTFORCE-APEX-01: Apex Entry Point Reads or Writes Caller-Controlled Records Without FLS

๐ŸŸก Medium ยท Broken Access Control

Detects @AuraEnabled, @InvocableMethod, @RemoteAction and @RestResource Apex that inserts, updates or upserts records whose field values the caller controls (SObject parameters, JSON.deserialize of the request body, invocable request wrappers, records built from a caller-supplied Id and fields, records handed to a Queueable) without field-level security: no 'as user', AccessLevel.USER_MODE, Security.stripInaccessible or per-field isCreateable/isUpdateable checks. An object-level CRUD check alone does not count. Also reports, at low severity, records selected by a caller-supplied value and returned without USER_MODE, SECURITY_ENFORCED or stripInaccessible. Medium; high when the class is enabled for a guest profile.

Detailsโ€‹

FieldValue
Rule IDAGENTFORCE-APEX-01
SeverityMedium
CategoryBroken Access Control
ComplianceSOC2_CC6, HIPAA

Remediationโ€‹

Enforce FLS on the records the caller sends: 'insert as user' / 'update as user', Database.* with AccessLevel.USER_MODE, or Security.stripInaccessible(AccessType.CREATABLE/UPDATABLE, records).getRecords() before the DML. For reads use WITH USER_MODE. Copy only the fields the operation needs into a new record instead of saving the deserialized object, and keep object-level CRUD checks as a second line of defence.

See Alsoโ€‹