PT-2026-70889 · Temporal Technologies+1 · Temporal Server+1

CVE-2026-65655

·

Published

2026-08-11

·

Updated

2026-08-11

CVSS v4.0

2.3

Low

VectorAV:N/AC:L/AT:P/PR:N/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions Temporal UI Server (affected versions not specified)
Description When OAuth authentication is enabled and TLS terminates at a reverse proxy that forwards the callback to the server over HTTP, the system incorrectly derives authentication-cookie Secure attributes from the proxy-to-server connection. This allows the server to issue access-token and refresh-token cookies without the Secure attribute, even if the browser login occurred over HTTPS. An attacker who can steer traffic for the UI hostname, prevent HTTPS connections, and serve the hostname over HTTP may expose these credentials via a same-site plaintext request. Recovered credentials can be replayed within the victim's permissions.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability. Implement effective HSTS (HTTP Strict Transport Security), a blocking HTTPS-only warning, or enable TLS re-encryption between the reverse proxy and Temporal UI Server.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-65655

Affected Products

Temporal Server
Ui-Server