CVE-2026-22584: Code Injection
Published Jan 9, 2026
·Updated
Improper Control of Generation of Code ('Code Injection') vulnerability in Salesforce Uni2TS on MacOS, Windows, Linux allows Leverage Executable Code in Non-Executable Files.This issue affects Uni2TS: through 1.2.0.
Affected Software
2 affected components
Salesforce Uni2TS<=1.2.0
Salesforce Uni2TS<2.0.0
Event History
Jan 9, 2026
CVE Published
via MITRE·10:10 PM
Data Sourced
via MITRE·10:10 PM
DescriptionWeakness
Data Sourced
via NVD·10:16 PM
DescriptionSeverityWeaknessAffected Software
Jan 13, 2026
News Published
via The Register·09:17 PM
News Published
via The Register·09:20 PM
Aug 28, 58046
Event
via FIRST·09:53 PM
Frequently Asked Questions
1
What is the severity of CVE-2026-22584?
The severity of CVE-2026-22584 is considered high due to its potential for arbitrary code execution.
2
How do I fix CVE-2026-22584?
To fix CVE-2026-22584, upgrade Salesforce Uni2TS to version 1.2.1 or later.
3
What platforms are affected by CVE-2026-22584?
CVE-2026-22584 affects Salesforce Uni2TS on MacOS, Windows, and Linux.
4
What does CVE-2026-22584 exploit?
CVE-2026-22584 exploits improper control of code generation which allows executing arbitrary code in non-executable files.
5
Is there any evidence of exploitation for CVE-2026-22584?
As of now, there are no confirmed reports of exploitation for CVE-2026-22584 in the wild.