Sunday, 13 September 2026
8 agent hacks today 7 vs yesterday (1)

Command injection in sf-mcp-server Salesforce MCP server (CVE-2026-26029)

CVE-2026-26029 describes a command injection flaw in sf-mcp-server, a Salesforce MCP server implementation for Claude for Desktop, caused by unsafe use of child_process.exec when building Salesforce CLI commands from user-controlled input. Exploitation allows arbitrary shell command execution with the privileges of the MCP server process.

Disclosed 11 February 2026 · Record updated 13 September 2026

Impact

Attackers could execute arbitrary shell commands with the privileges of the MCP server process on systems running the vulnerable Salesforce MCP server.

Our coverage

No articles linked to this incident yet.

Sources

  1. nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-26029