PT-2026-30712 · Salesforce.Com · Workbench

·

CVE-2026-35178

·

Published

2026-04-06

·

Updated

2026-04-06

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Workbench versions prior to 65.0.0
Description Workbench, a suite of tools for interacting with Salesforce.com organizations via the Force.com APIs, contains a remote code execution issue in the timezone conversion flow. The issue arises from unsafe processing of attacker-controlled cookie values. This affects administrators and developers using Workbench.
Recommendations Update Workbench to version 65.0.0 or later.

Exploit

Fix

RCE

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-35178
GHSA-JW63-M86R-2JXC

Affected Products

Workbench