PatchSiren

forceworkbench CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

CRITICAL forceworkbench CVE published 2026-04-06

CVE-2026-35178

CVE-2026-35178 is a remote code execution vulnerability in Workbench, a suite of tools for administrators and developers to interact with Salesforce.com organizations via the Force.com APIs. The vulnerability exists in the timezone conversion flow, which processes attacker-controlled cookie values in an unsafe manner. This issue was fixed in version 65.0.0. The vulnerability has a CVSS score of 9.3 and is [truncated]