high severityConfidence highHistorical record

Temporal namespace write can shell the Worker Service host

Temporal Server 1.31.0 before 1.31.3 includes a Worker Controller subprocess compute provider that executes caller-supplied program and argv on the Worker Service host when an authenticated namespace writer configures a worker deployment version. The default compute-provider allowlist is unset, so every registered provider including subprocess is permitted. Sibling CVE-2026-87858 lets a namespace writer retarget completion callbacks at the internal frontend as system administrator via a caller-controlled source header when an internal frontend HTTP port and callback allowlist are in play. Fixed trains: 1.30.7, 1.31.3, 1.32.0+.

Also tracked as CVE-2026-89139 · CVE-2026-87858 · Temporal Worker subprocess RCE · Temporal callback source header admin

First observed
Sep 21, 2026
Last observed
Sep 21, 2026
Last reviewed
Sep 21, 2026
Tracking ended
Sep 21, 2026

Uncertainty and limitations

Read the evidence limits before acting on this record.

Both CVEs need authenticated namespace write. CVE-2026-87858 also needs an internal frontend with HTTP enabled and a non-empty callback allowlist. Confirm your exact image/chart tag against Temporal release notes before treating a build as fixed.

  • Authenticated namespace write required for both CVEs; not unauthenticated internet RCE.
  • CVE-2026-87858 requires internal frontend HTTP plus non-empty callback allowlist; stock empty allowlist denies external callbacks.
  • Temporal Cloud is out of scope for this self-hosted Temporal Server campaign.
  • Does not invent exploitation status; not on CISA KEV as of publish.

Guard coverage and policy

What Guard's reviewed assertions do and do not claim for this campaign, and the reviewed starting points for defense.

No Guard coverage mapping is published for this record.

No campaign-specific policy guidance is published.

Safe next step. Campaign guidance is defensive context. It does not auto-apply policy or claim universal campaign coverage.

Timeline

Reviewed events, oldest first, each tied to a verified source.

  1. Disclosure

    CVE-2026-89139 and sibling CVE-2026-87858 published for Temporal Server Worker subprocess RCE and admin callback retarget.

  2. Vendor action

    Temporal shipped fixed trains 1.30.7, 1.31.3, and 1.32.0 with patches for the subprocess provider and callback source-header inspection.

  3. Update

    HOL Guard published the operator blog covering CVE-2026-89139 clustered with CVE-2026-87858.

Publication clock: 1.8 hours from reviewed disclosure timestamp to HOL publication; 24-hour high target; within target.

Reviewed artifacts

The specific artifacts this record concerns, as reviewed. Names and versions are shown as text; a registry link is not recorded here.

  • Temporal Server@>=1.31.0 <1.31.3genericpackage
  • Temporal Server@>=1.30.0 <1.30.7genericpackage

Sources

Every claim on this record is traceable to the sources below.

Reviewed in full by HOL Guard Security Publishing.

Published
Last full review
Last modified

Report a correction

Record HGTC-2026-49979A99