PT-2026-96073 · Temporal · Temporal Server

CVE-2026-16652

·

Published

2026-09-21

·

Updated

2026-09-21

CVSS v4.0

7.1

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Temporal Server (affected versions not specified)
Description An authenticated user with namespace write permissions can cause a denial of service by creating or updating a Schedule that uses a fine-grained cadence combined with an exclusion calendar that rejects all candidate times. This occurs because the server does not limit the work performed when searching for the next action time, leading to excessive CPU consumption in the Frontend and Schedule worker components. Additionally, a persisted specification may cause the associated Schedule Workflow to fail and retry repeatedly, sustaining high CPU usage until the Schedule is deleted or the Workflow is terminated.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-16652

Affected Products

Temporal Server