Server Callback Vulnerability in Temporal by Temporal.io
CVE-2026-87858
What is CVE-2026-87858?
A vulnerability exists in the Temporal Server that allows an authenticated user with minimal permissions to craft a malicious HTTP callback. The attacker can exploit this vulnerability to orchestrate requests that can modify, terminate, or delete workflows across different namespaces, effectively bypassing normal permission restrictions. This risk arises when appropriate allowlist rules exist for URL hosts and the internal frontend is improperly configured. Such configurations can lead to unauthorized state-changing actions on the server. Notably, this issue affects various versions of the Temporal Server, emphasizing the need for rigorous configuration and security audits on deployed instances.
Affected Version(s)
Temporal Server 1.30.0 < 1.30.7
Temporal Server 1.31.0 < 1.31.3
Temporal Server 1.25.0 <= 1.29.7
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
