PT-2026-96079 · Unknown · Temporal Server

CVE-2026-89139

·

Published

2026-09-21

·

Updated

2026-09-21

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Temporal Server versions 1.31.0 through 1.31.2
Description The Worker Service in Temporal Server includes a Worker Controller Instance module that registers a compute provider named subprocess. This provider allows the execution of commands on the host machine running the Worker Service. The issue arises because the program name and argument vector are taken from the caller's request instead of the operator configuration. An authenticated user with a write role in a single namespace can configure a worker deployment version to execute arbitrary commands on the host under the server process account. This execution occurs immediately upon validation of the specification. Since the Worker Service holds persistence credentials for all namespaces and the cluster's TLS material, an attacker can compromise the entire cluster. The vulnerability is active if the workercontroller.compute providers.enabled setting is unset or includes subprocess, and if authorization is configured. To identify existing compromised configurations, the DescribeWorkerDeploymentVersion function can be used to check if any scaling group uses the subprocess compute provider type.
Recommendations Update Temporal Server to version 1.31.3 or later. Restrict the workercontroller.compute providers.enabled dynamic configuration setting to exclude the subprocess provider. Avoid using the subprocess compute provider type in worker deployment versions.

Fix

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-89139

Affected Products

Temporal Server