CVE-2026-35178 is a remote code execution vulnerability in Salesforce Workbench versions prior to 65.0.0, a suite of administrative and developer tools for interacting with Force.com APIs. The vulnerability exists in the timezone conversion flow, which improperly processes attacker-controlled cookie values without adequate safeguards. This flaw has been remediated in version 65.0.0 and later. The vulnerability carries a CRITICAL CVSS v3.1 score of 9.8, reflecting its severe nature across all dimensions. The attack requires only network access with no special privileges or user interaction, making it trivially exploitable. Successful exploitation grants attackers complete system compromise, including confidentiality, integrity, and availability breaches. There is currently no evidence of active exploitation in the wild, and the vulnerability does not appear on the KEV catalog or hot exploit lists. However, the relatively straightforward attack vector and network accessibility suggest organizations should prioritize patching to version 65.0.0 or later as a high-priority security action. The EPSS score of 0.003 indicates lower predicted likelihood of near-term exploitation compared to the broader CVE population.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 65.0.0CPE matchmatch criteria | cpe:2.3:a:forceworkbench:forceworkbench:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.