PT-2026-70889 · Temporal Technologies+1 · Temporal Server+1
CVE-2026-65655
·
Published
2026-08-11
·
Updated
2026-08-11
CVSS v4.0
2.3
Low
| Vector | AV:N/AC:L/AT:P/PR:N/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
Temporal UI Server (affected versions not specified)
Description
When OAuth authentication is enabled and TLS terminates at a reverse proxy that forwards the callback to the server over HTTP, the system incorrectly derives authentication-cookie Secure attributes from the proxy-to-server connection. This allows the server to issue
access-token and refresh-token cookies without the Secure attribute, even if the browser login occurred over HTTPS. An attacker who can steer traffic for the UI hostname, prevent HTTPS connections, and serve the hostname over HTTP may expose these credentials via a same-site plaintext request. Recovered credentials can be replayed within the victim's permissions.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Implement effective HSTS (HTTP Strict Transport Security), a blocking HTTPS-only warning, or enable TLS re-encryption between the reverse proxy and Temporal UI Server.
Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Temporal Server
Ui-Server