Google: remote code execution
Critical9.8CVE-2026-35178 · Published May 28, 2026
### Summary Workbench https://workbench.developerforce.com, a popular open-source Salesforce administration tool (all versions up to 53.0.0), contains critical Remote Code Execution (RCE) and Cross-Site Scripting (XSS) vulnerabilities (assigned CVE-2026-35178). The XSS vulnerability is pre-authentication and can be used to write a malicious cookie. This cookie initializes the RCE exploit, which triggers once an authenticated user accesses specific pages that format timestamps. Furthermore, because Workbench stores users' OAuth tokens in session, attackers can leverage these vulnerabilities to hijack sessions and deploy persistent Apex backdoors to any Salesforce organization managed by the affected administrator. ### Severity CRITICAL #### Motivation This vulnerability is classified as CRITICAL due to the high ease of exploit delivery, the potential for low-privilege escalation, and the catastrophic downstream impact (blast radius). • Pre-authentication Delivery: The Reflected XSS allows exploits to be staged stealthily before a user even authenticates, such as via hidden iFrames. • Low-Privilege Escalation: An attacker with a standard, low-privilege Salesfo...
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| github.com/kopia/kopia Go | < 0.23.0 | 0.23.0 |
Details and references
### Summary Workbench https://workbench.developerforce.com, a popular open-source Salesforce administration tool (all versions up to 53.0.0), contains critical Remote Code Execution (RCE) and Cross-Site Scripting (XSS) vulnerabilities (assigned CVE-2026-35178). The XSS vulnerability is pre-authentication and can be used to write a malicious cookie. This cookie initializes the RCE exploit, which triggers once an authenticated user accesses specific pages that format timestamps. Furthermore, because Workbench stores users' OAuth tokens in session, attackers can leverage these vulnerabilities to hijack sessions and deploy persistent Apex backdoors to any Salesforce organization managed by the affected administrator. ### Severity CRITICAL #### Motivation This vulnerability is classified as CRITICAL due to the high ease of exploit delivery, the potential for low-privilege escalation, and the catastrophic downstream impact (blast radius). • Pre-authentication Delivery: The Reflected XSS allows exploits to be staged stealthily before a user even authenticates, such as via hidden iFrames. • Low-Privilege Escalation: An attacker with a standard, low-privilege Salesforce trial account can authenticate to a Workbench instance (including the public Developerforce deployment hosting ~200, 000 monthly active users) and exploit the RCE to escalate privileges. • Downstream Compromise: Once RCE is achieved, the attacker can harvest Salesforce OAuth tokens stored in session and deploy per
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Severity from
- GitHub (reviewed advisory)
More Google advisories
All Google| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Jul 1 | Google Chrome: out-of-bounds write | High8.8 | 150.0.7871.46 |
| Jul 1 | Google Chrome: buffer overflow | High8.8 | 150.0.7871.46 |
| Jul 1 | Google Chrome: out-of-bounds read | Medium6.5 | 150.0.7871.46 |
| Jul 1 | Google Chrome: remote code execution | High8.8 | 150.0.7871.46 |
| Jul 1 | Google Chrome: remote attacker could potentially perform a sandbox escape | Critical9.6 | 150.0.7871.46 |
| Jul 1 | Google Chrome: spoofing | Medium6.5 | 150.0.7871.46 |