Skip to content
Release: Australia · Updated: 2026-03-12 · Official documentation · View source

Prevent Unauthenticated Access to Virtual Agent Embedded Web Client

Learn how to configure the sn_va_web_client_app_embed table to block unauthenticated users from accessing embedded web clients.

The UI page sn_va_web_client_app_embed, which is an embedded web client for Virtual Agent, contains the ACL marked 'true' in the sys_public table Out of Box. It has been confirmed that there are use cases where public accessibility is needed however this is not a security best practice to set it to default publicly accessible.

Deactivate ui page sn_va_web_client_app_embed from the Public Pages [sys_public] table if embedded web client is not needed for unauthenticated users

More information

AttributeDescription
Configuration namesn_va_web_client_app_embed
Configuration typeUI Page\(sys\_ui\_page\_list.do\)
Data typetable
Recommended valueThe Public Pages \[sys\_public\] table record with sys\_id of `04b1905473222300e985658b4cf6a7ef` does exist or is not active.
Default valueNot available \(this is a table value\)
CategoryAccess control
Security risk- Severity score: 7.5 - CVSS score: High - Security risk details: Sensitive information may be exposed to unauthenticated users.
Dependencies and prerequisitesNone

Parent Topic:Access control