Vulnerability in Temporal Server's Worker Service Affects Namespace Security
CVE-2026-89139

8.7HIGH

Key Information:

Vendor
CVE Published:
21 September 2026

What is CVE-2026-89139?

The Temporal Server's Worker Service includes a vulnerability where an authenticated user with write permissions can manipulate worker deployments to execute commands of their choice on the host machine. The flaw lies in how the Worker Service registers compute providers, particularly the subprocess provider, which operates under the server process's credentials. This allows attackers to bypass namespace boundaries and potentially compromise the entire cluster by misconfiguring deployment settings. Without proper restrictions in place, affected versions of Temporal Server can expose serious security risks, affecting not only the namespace in which the user operates but also the overall integrity of the system.

Affected Version(s)

Temporal Server 1.31.0 < 1.31.3

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Reported internally at Temporal Technologies, Inc.
.