PT-2026-29583 · Temporal · Temporal Server

CVE-2026-5199

·

Published

2026-04-01

·

Updated

2026-07-30

CVSS v4.0

2.3

Low

VectorAV:N/AC:H/AT:P/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:L/SA:L/S:N/AU:Y/R:U/RE:M
Name of the Vulnerable Software and Affected Versions Temporal Server versions 1.29.0 and later
Description A user with a writer role in an attacker-controlled namespace could signal, delete, and reset workflows or activities in a victim namespace on the same cluster. Exploitation requires the attacker to know or guess specific victim workflow ID(s) and, for signal operations, signal names. This issue stemmed from a bug introduced in Temporal Server v1.29.0, where the server incorrectly allowed an attacker to control the namespace name value instead of using a trusted value within the batch activity code. The batch activity validated the namespace ID but did not verify the namespace name against the worker's bound namespace, enabling privileged credentials to operate on an arbitrary namespace. Exploitation requires a server configuration with cross-namespace authorization, such as the deployment of the internal-frontend service or equivalent TLS-based authorization for internal identities. This vulnerability also impacted Temporal Cloud when the attacker and victim namespaces were on the same cell.
Recommendations Update Temporal Server to a version later than 1.29.0.

Exploit

Fix

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CLEANSTART-2026-SP73148
CVE-2026-5199
GHSA-XPG8-3HHP-P7W8
GO-2026-5766
OPENSUSE-SU-2026:21483-1

Affected Products

Temporal Server