Temporal namespace write can shell the Worker Service host
Temporal Server 1.31.0 before 1.31.3 includes a Worker Controller subprocess compute provider that executes caller-supplied program and argv on the Worker Service host when an authenticated namespace writer configures a worker deployment version. The default compute-provider allowlist is unset, so every registered provider including subprocess is permitted. Sibling CVE-2026-87858 lets a namespace writer retarget completion callbacks at the internal frontend as system administrator via a caller-controlled source header when an internal frontend HTTP port and callback allowlist are in play. Fixed trains: 1.30.7, 1.31.3, 1.32.0+.
Also tracked as CVE-2026-89139 · CVE-2026-87858 · Temporal Worker subprocess RCE · Temporal callback source header admin
- First observed
- Sep 21, 2026
- Last observed
- Sep 21, 2026
- Last reviewed
- Sep 21, 2026
- Tracking ended
- Sep 21, 2026
Record exports
Uncertainty and limitations
Read the evidence limits before acting on this record.
Both CVEs need authenticated namespace write. CVE-2026-87858 also needs an internal frontend with HTTP enabled and a non-empty callback allowlist. Confirm your exact image/chart tag against Temporal release notes before treating a build as fixed.
- Authenticated namespace write required for both CVEs; not unauthenticated internet RCE.
- CVE-2026-87858 requires internal frontend HTTP plus non-empty callback allowlist; stock empty allowlist denies external callbacks.
- Temporal Cloud is out of scope for this self-hosted Temporal Server campaign.
- Does not invent exploitation status; not on CISA KEV as of publish.
Guard coverage and policy
What Guard's reviewed assertions do and do not claim for this campaign, and the reviewed starting points for defense.
No Guard coverage mapping is published for this record.
No campaign-specific policy guidance is published.
Safe next step. Campaign guidance is defensive context. It does not auto-apply policy or claim universal campaign coverage.
Timeline
Reviewed events, oldest first, each tied to a verified source.
- Disclosure
CVE-2026-89139 and sibling CVE-2026-87858 published for Temporal Server Worker subprocess RCE and admin callback retarget.
- Vendor action
Temporal shipped fixed trains 1.30.7, 1.31.3, and 1.32.0 with patches for the subprocess provider and callback source-header inspection.
- Update
HOL Guard published the operator blog covering CVE-2026-89139 clustered with CVE-2026-87858.
Publication clock: 1.8 hours from reviewed disclosure timestamp to HOL publication; 24-hour high target; within target.
Reviewed artifacts
The specific artifacts this record concerns, as reviewed. Names and versions are shown as text; a registry link is not recorded here.
Temporal Server@>=1.31.0 <1.31.3genericpackageTemporal Server@>=1.30.0 <1.30.7genericpackage
Sources
Every claim on this record is traceable to the sources below.
- NVD CVE-2026-89139vulnerability database · observed September 21, 2026
- NVD CVE-2026-87858vulnerability database · observed September 21, 2026
- temporal PR 12021 auto-scaled-workers bumpmaintainer advisory · observed September 21, 2026
- temporal-auto-scaled-workers PR 129maintainer advisory · observed September 21, 2026
- temporal PR 11965 callback source header opt-inmaintainer advisory · observed September 21, 2026
- Temporal Server v1.31.3 releasemaintainer advisory · observed September 21, 2026
- Temporal Server v1.30.7 releasemaintainer advisory · observed September 21, 2026
- HOL Guard operator write-upother primary · observed September 21, 2026
Reviewed in full by HOL Guard Security Publishing.
- Published
- Last full review
- Last modified
Record HGTC-2026-49979A99