PT-2026-96078 · Temporal · Temporal Server

CVE-2026-87858

·

Published

2026-09-21

·

Updated

2026-09-21

CVSS v4.0

7.2

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions Temporal Server versions 1.25.0 through 1.30.x
Description An authenticated user with write permissions in a single namespace can trigger unauthorized administrative actions by exploiting how the server identifies internal Workflow completion callbacks. By attaching a callback with a URL host that matches the configured allowlist and including a non-empty source header, the History service re-targets the request to the local internal frontend. If the internal frontend has its HTTP API enabled, it authorizes these requests as a system administrator without requiring authentication. This allows an attacker to perform state-changing HTTP POST requests against the administrative API, enabling them to terminate workflows, register or delete namespaces, and modify namespace configurations in areas where they lack permission. This issue affects both HSM and CHASM callback delivery implementations. In versions 1.30.0 and later, any non-empty source header triggers the behavior, while in versions 1.25.0 through 1.29.7, the header must exactly match a specific cluster ID.
Recommendations For versions 1.25.0 through 1.30.x, ensure that the services.internal-frontend.rpc.httpPort is set to zero or that the component.callbacks.allowedAddresses allowlist is empty to prevent external callback URLs from being processed. As a temporary mitigation, restrict the use of the source header in completion callbacks to prevent the re-targeting of requests to the internal frontend.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-87858

Affected Products

Temporal Server