Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-35178

33
FAUCET Score

CVE-2026-35178 is a remote code execution vulnerability in Salesforce Workbench versions prior to 65.0.0, a suite of administrative and developer tools for interacting with Force.com APIs. The vulnerability exists in the timezone conversion flow, which improperly processes attacker-controlled cookie values without adequate safeguards. This flaw has been remediated in version 65.0.0 and later. The vulnerability carries a CRITICAL CVSS v3.1 score of 9.8, reflecting its severe nature across all dimensions. The attack requires only network access with no special privileges or user interaction, making it trivially exploitable. Successful exploitation grants attackers complete system compromise, including confidentiality, integrity, and availability breaches. There is currently no evidence of active exploitation in the wild, and the vulnerability does not appear on the KEV catalog or hot exploit lists. However, the relatively straightforward attack vector and network accessibility suggest organizations should prioritize patching to version 65.0.0 or later as a high-priority security action. The EPSS score of 0.003 indicates lower predicted likelihood of near-term exploitation compared to the broader CVE population.

Impacted Technologies

VendorProductVersion(s)CPE
< 65.0.0CPE matchmatch criteria
cpe:2.3:a:forceworkbench:forceworkbench:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 4.0

9.3CRITICAL

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Attack Vector
NETWORK
Attack Complexity
LOW
Attack Requirements
NONE
Privileges Required
NONE
User Interaction
PASSIVE
VS Confidentiality
HIGH
VS Integrity
HIGH
VS Availability
NONE
SS Confidentiality
HIGH
SS Integrity
HIGH
SS Availability
NONE
Exploit Maturity
NOT_DEFINED
CvssVersion
4.0

Exploit Intelligence

EPSS Score
0.49%
Probability of exploitation in next 30 days
EPSS Percentile
39.4%
Percentile rank of EPSS score among Peer Group
As of 2026-07-26
Model: v2026.06.15
This CVE's current EPSS score of 0.0049 is in the 17th percentile among its peer group of 36,835 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Patches (1)

github_advisoryvendor investigatingvia nvd_reference
View patch

References

github.com / forceworkbench/forceworkbench/pull/869
Issue TrackingVendor Advisory
github.com / forceworkbench/forceworkbench/security/advisories/GHSA-jw63-m86r-2jxc
Vendor Advisory