CVE-2026-35178

Workbench is a suite of tools for administrators and developers to interact with Salesforce.com organizations via the Force.com APIs. Prior to 65.0.0, Workbench contains remote code execution vulnerability in the timezone conversion flow, which processes attacker-controlled cookie values in an unsafe manner. This vulnerability is fixed in 65.0.0.
Configurations

Configuration 1 (hide)

cpe:2.3:a:forceworkbench:forceworkbench:*:*:*:*:*:*:*:*

History

24 Jul 2026, 21:10

Type Values Removed Values Added
Summary
  • (es) Workbench es un conjunto de herramientas para que administradores y desarrolladores interactúen con organizaciones de Salesforce.com a través de las API de Force.com. Antes de la versión 65.0.0, Workbench contiene una vulnerabilidad de ejecución remota de código en el flujo de conversión de zona horaria, que procesa valores de cookie controlados por el atacante de forma insegura. Esta vulnerabilidad está corregida en la versión 65.0.0.

16 Apr 2026, 04:10

Type Values Removed Values Added
References () https://github.com/forceworkbench/forceworkbench/pull/869 - () https://github.com/forceworkbench/forceworkbench/pull/869 - Issue Tracking, Vendor Advisory
References () https://github.com/forceworkbench/forceworkbench/security/advisories/GHSA-jw63-m86r-2jxc - () https://github.com/forceworkbench/forceworkbench/security/advisories/GHSA-jw63-m86r-2jxc - Vendor Advisory
CPE cpe:2.3:a:forceworkbench:forceworkbench:*:*:*:*:*:*:*:*
First Time Forceworkbench
Forceworkbench forceworkbench
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8

06 Apr 2026, 20:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-04-06 20:16

Updated : 2026-07-24 21:10


NVD link : CVE-2026-35178

Mitre link : CVE-2026-35178

CVE.ORG link : CVE-2026-35178


JSON object : View

Products Affected

forceworkbench

  • forceworkbench
CWE
CWE-94

Improper Control of Generation of Code ('Code Injection')