OAuth Authentication Vulnerability in Temporal UI Server by Temporal
CVE-2026-65655

2.3LOW

Key Information:

Vendor
CVE Published:
11 August 2026

What is CVE-2026-65655?

The vulnerability arises when OAuth authentication is enabled and TLS terminates at a reverse proxy forwarding the callback to the Temporal UI Server via HTTP. This misconfiguration allows the server to issue access-token and refresh-token cookies without secure attributes, posing a risk of credential leakage. If a user interacts with malicious content while logged in, their credentials may be at risk if traffic steering is achieved by the attacker. Preventative measures such as effective HSTS, strict HTTPS warnings, or TLS re-encryption can mitigate the vulnerability, ensuring the integrity of user sessions.

Affected Version(s)

Temporal UI Server 2.7.0 < 2.53.2

References

CVSS V4

Score:
2.3
Severity:
LOW
Confidentiality:
Low
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

An external security researcher who reported this issue responsibly to Temporal Technologies
.