Vulnerability in Temporal Server's Worker Service Affects Namespace Security
CVE-2026-89139
What is CVE-2026-89139?
The Temporal Server's Worker Service includes a vulnerability where an authenticated user with write permissions can manipulate worker deployments to execute commands of their choice on the host machine. The flaw lies in how the Worker Service registers compute providers, particularly the subprocess provider, which operates under the server process's credentials. This allows attackers to bypass namespace boundaries and potentially compromise the entire cluster by misconfiguring deployment settings. Without proper restrictions in place, affected versions of Temporal Server can expose serious security risks, affecting not only the namespace in which the user operates but also the overall integrity of the system.
Affected Version(s)
Temporal Server 1.31.0 < 1.31.3
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
