← Πίσω στην αναζήτηση CVE

CVE-2026-5199

Temporal Server

Περιγραφή

A writer role user in an attacker-controlled namespace could signal, delete, and reset workflows or activities in a victim namespace on the same cluster. Exploitation requires the attacker to know or guess specific victim workflow ID(s) and, for signal operations, signal names. This was due to a bug introduced in Temporal Server v1.29.0 which inadvertently allowed an attacker to control the namespace name value instead of using the server-s own trusted name value within the batch activity code. The batch activity validated the namespace ID but did not cross-check the namespace name against the worker-s bound namespace, allowing the per-namespace worker-s privileged credentials to operate on an arbitrary namespace. Exploitation requires a server configuration where internal components have cross-namespace authorization, such as deployment of the internal-frontend service or equivalent TLS-based authorization for internal identities. This vulnerability also impacted Temporal Cloud when t...

CVSS 2.3EPSS 0.248%Κίνδυνος 0.24
Προβολή πηγής
Δημοσίευση
2026-04-01 18:16:31
Επηρεαζόμενες εκδόσεις
cannotmatch
Τύπος
Core software
Διάνυσμα
CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:N/AU:Y/R:U/V:X/RE:M/U:X