{
  "schemaVersion": "guard-threat-campaign/v1",
  "id": "HGTC-2026-49979A99",
  "slug": "cve-2026-89139-temporal-worker-subprocess-rce-callback-admin",
  "title": "Temporal namespace write can shell the Worker Service host",
  "aliases": [
    "CVE-2026-89139",
    "CVE-2026-87858",
    "Temporal Worker subprocess RCE",
    "Temporal callback source header admin"
  ],
  "summary": "Temporal Server 1.31.0 before 1.31.3 includes a Worker Controller subprocess compute provider that executes caller-supplied program and argv on the Worker Service host when an authenticated namespace writer configures a worker deployment version. The default compute-provider allowlist is unset, so every registered provider including subprocess is permitted. Sibling CVE-2026-87858 lets a namespace writer retarget completion callbacks at the internal frontend as system administrator via a caller-controlled source header when an internal frontend HTTP port and callback allowlist are in play. Fixed trains: 1.30.7, 1.31.3, 1.32.0+.",
  "status": "published",
  "severity": "high",
  "confidence": "high",
  "uncertainty": "Both CVEs need authenticated namespace write. CVE-2026-87858 also needs an internal frontend with HTTP enabled and a non-empty callback allowlist. Confirm your exact image/chart tag against Temporal release notes before treating a build as fixed.",
  "firstObservedAt": "2026-09-21T11:41:23.342Z",
  "lastObservedAt": "2026-09-21T13:26:39.796Z",
  "publishedAt": "2026-09-21T13:31:11.615Z",
  "reviewedAt": "2026-09-21T13:31:01.780Z",
  "expiresAt": "2026-09-21T13:26:39.796Z",
  "reviewer": "HOL Guard Security Publishing",
  "sources": [
    {
      "id": "nvd-89139",
      "label": "NVD CVE-2026-89139",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-89139",
      "sourceType": "vulnerability_database",
      "observedAt": "2026-09-21T12:17:24.440Z"
    },
    {
      "id": "nvd-87858",
      "label": "NVD CVE-2026-87858",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-87858",
      "sourceType": "vulnerability_database",
      "observedAt": "2026-09-21T12:17:22.230Z"
    },
    {
      "id": "pr-12021",
      "label": "temporal PR 12021 auto-scaled-workers bump",
      "url": "https://github.com/temporalio/temporal/pull/12021",
      "sourceType": "maintainer_advisory",
      "observedAt": "2026-09-21T13:26:39.796Z"
    },
    {
      "id": "pr-129",
      "label": "temporal-auto-scaled-workers PR 129",
      "url": "https://github.com/temporalio/temporal-auto-scaled-workers/pull/129",
      "sourceType": "maintainer_advisory",
      "observedAt": "2026-09-21T13:26:39.796Z"
    },
    {
      "id": "pr-11965",
      "label": "temporal PR 11965 callback source header opt-in",
      "url": "https://github.com/temporalio/temporal/pull/11965",
      "sourceType": "maintainer_advisory",
      "observedAt": "2026-09-21T13:26:39.796Z"
    },
    {
      "id": "rel-1313",
      "label": "Temporal Server v1.31.3 release",
      "url": "https://github.com/temporalio/temporal/releases/tag/v1.31.3",
      "sourceType": "maintainer_advisory",
      "observedAt": "2026-09-21T13:26:39.796Z"
    },
    {
      "id": "rel-1307",
      "label": "Temporal Server v1.30.7 release",
      "url": "https://github.com/temporalio/temporal/releases/tag/v1.30.7",
      "sourceType": "maintainer_advisory",
      "observedAt": "2026-09-21T13:26:39.796Z"
    },
    {
      "id": "hol-blog",
      "label": "HOL Guard operator write-up",
      "url": "https://hol.org/blog/cve-2026-89139-temporal-worker-subprocess-rce-callback-admin",
      "sourceType": "other_primary",
      "observedAt": "2026-09-21T13:26:39.796Z"
    }
  ],
  "artifacts": [
    {
      "id": "temporal-server-131",
      "artifactClass": "package",
      "ecosystem": "generic",
      "name": "Temporal Server",
      "version": ">=1.31.0 <1.31.3",
      "defanged": false
    },
    {
      "id": "temporal-server-130",
      "artifactClass": "package",
      "ecosystem": "generic",
      "name": "Temporal Server",
      "version": ">=1.30.0 <1.30.7",
      "defanged": false
    }
  ],
  "indicators": [],
  "timeline": [
    {
      "id": "disclosure",
      "occurredAt": "2026-09-21T11:41:23.342Z",
      "eventType": "disclosure",
      "summary": "CVE-2026-89139 and sibling CVE-2026-87858 published for Temporal Server Worker subprocess RCE and admin callback retarget.",
      "sourceIds": [
        "nvd-89139",
        "nvd-87858"
      ]
    },
    {
      "id": "vendor-fix",
      "occurredAt": "2026-09-21T11:41:23.342Z",
      "eventType": "vendor_action",
      "summary": "Temporal shipped fixed trains 1.30.7, 1.31.3, and 1.32.0 with patches for the subprocess provider and callback source-header inspection.",
      "sourceIds": [
        "rel-1313",
        "rel-1307",
        "pr-12021",
        "pr-11965"
      ]
    },
    {
      "id": "hol-publish",
      "occurredAt": "2026-09-21T13:26:39.796Z",
      "eventType": "other",
      "summary": "HOL Guard published the operator blog covering CVE-2026-89139 clustered with CVE-2026-87858.",
      "sourceIds": [
        "hol-blog"
      ]
    }
  ],
  "coverage": [],
  "policies": [],
  "limitations": [
    "Authenticated namespace write required for both CVEs; not unauthenticated internet RCE.",
    "CVE-2026-87858 requires internal frontend HTTP plus non-empty callback allowlist; stock empty allowlist denies external callbacks.",
    "Temporal Cloud is out of scope for this self-hosted Temporal Server campaign.",
    "Does not invent exploitation status; not on CISA KEV as of publish."
  ],
  "correctionHref": "/guard/security/campaigns/cve-2026-89139-temporal-worker-subprocess-rce-callback-admin/corrections"
}
