AGENTFORCE-APEX-02: Entry Point Without Sharing Runs Privileged Operation on Caller-Supplied Records
๐ก Medium ยท Broken Access Control
Detects externally callable Apex (invocable, @AuraEnabled, @RemoteAction, REST) in a class with no sharing keyword or 'without sharing' that runs Approval.lock/unlock/process, updates/upserts/deletes caller-supplied records or ids, or enqueues a Queueable that writes caller-supplied records, with no ownership or record-access check. The operation runs in system context on any record id the caller names. Medium; high when the class is enabled for a guest profile.
Detailsโ
| Field | Value |
|---|---|
| Rule ID | AGENTFORCE-APEX-02 |
| Severity | Medium |
| Category | Broken Access Control |
| Compliance | SOC2_CC6, HIPAA |
Remediationโ
Declare the class 'with sharing' (and the Queueable it enqueues), run the DML 'as user' or with AccessLevel.USER_MODE, and check UserRecordAccess (HasEditAccess) or ownership for every caller-supplied id before locking, unlocking or writing it. Restrict who can run the flow or agent action with a custom permission.