Server Callback Vulnerability in Temporal by Temporal.io
CVE-2026-87858

7.2HIGH

Key Information:

Vendor
CVE Published:
21 September 2026

What is CVE-2026-87858?

A vulnerability exists in the Temporal Server that allows an authenticated user with minimal permissions to craft a malicious HTTP callback. The attacker can exploit this vulnerability to orchestrate requests that can modify, terminate, or delete workflows across different namespaces, effectively bypassing normal permission restrictions. This risk arises when appropriate allowlist rules exist for URL hosts and the internal frontend is improperly configured. Such configurations can lead to unauthorized state-changing actions on the server. Notably, this issue affects various versions of the Temporal Server, emphasizing the need for rigorous configuration and security audits on deployed instances.

Affected Version(s)

Temporal Server 1.30.0 < 1.30.7

Temporal Server 1.31.0 < 1.31.3

Temporal Server 1.25.0 <= 1.29.7

References

CVSS V4

Score:
7.2
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

An external security researcher who reported this issue responsibly to Temporal Technologies
.