OAuth Authentication Vulnerability in Temporal UI Server by Temporal
CVE-2026-65655
2.3LOW
What is CVE-2026-65655?
The vulnerability arises when OAuth authentication is enabled and TLS terminates at a reverse proxy forwarding the callback to the Temporal UI Server via HTTP. This misconfiguration allows the server to issue access-token and refresh-token cookies without secure attributes, posing a risk of credential leakage. If a user interacts with malicious content while logged in, their credentials may be at risk if traffic steering is achieved by the attacker. Preventative measures such as effective HSTS, strict HTTPS warnings, or TLS re-encryption can mitigate the vulnerability, ensuring the integrity of user sessions.
Affected Version(s)
Temporal UI Server 2.7.0 < 2.53.2
References
CVSS V4
Score:
2.3
Severity:
LOW
Confidentiality:
Low
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown
Timeline
Vulnerability published
Vulnerability Reserved
Credit
An external security researcher who reported this issue responsibly to Temporal Technologies
