PT-2026-96079 · Unknown · Temporal Server
CVE-2026-89139
·
Published
2026-09-21
·
Updated
2026-09-21
CVSS v4.0
8.7
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Temporal Server versions 1.31.0 through 1.31.2
Description
The Worker Service in Temporal Server includes a Worker Controller Instance module that registers a compute provider named subprocess. This provider allows the execution of commands on the host machine running the Worker Service. The issue arises because the program name and argument vector are taken from the caller's request instead of the operator configuration. An authenticated user with a write role in a single namespace can configure a worker deployment version to execute arbitrary commands on the host under the server process account. This execution occurs immediately upon validation of the specification. Since the Worker Service holds persistence credentials for all namespaces and the cluster's TLS material, an attacker can compromise the entire cluster. The vulnerability is active if the
workercontroller.compute providers.enabled setting is unset or includes subprocess, and if authorization is configured. To identify existing compromised configurations, the DescribeWorkerDeploymentVersion function can be used to check if any scaling group uses the subprocess compute provider type.Recommendations
Update Temporal Server to version 1.31.3 or later.
Restrict the
workercontroller.compute providers.enabled dynamic configuration setting to exclude the subprocess provider.
Avoid using the subprocess compute provider type in worker deployment versions.Fix
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Temporal Server