{"type":"bundle","id":"bundle--1486c45e-6e48-5663-892e-03529ae9d8c0","objects":[{"type":"campaign","spec_version":"2.1","id":"campaign--0fe31250-3a1b-5823-b04b-316fa433db16","created":"2026-09-21T13:31:11.615Z","modified":"2026-09-21T13:31:11.615Z","name":"Temporal namespace write can shell the Worker Service host","description":"Temporal Server 1.31.0 before 1.31.3 includes a Worker Controller subprocess compute provider that executes caller-supplied program and argv on the Worker Service host when an authenticated namespace writer configures a worker deployment version. The default compute-provider allowlist is unset, so every registered provider including subprocess is permitted. Sibling CVE-2026-87858 lets a namespace writer retarget completion callbacks at the internal frontend as system administrator via a caller-controlled source header when an internal frontend HTTP port and callback allowlist are in play. Fixed trains: 1.30.7, 1.31.3, 1.32.0+.","aliases":["CVE-2026-89139","CVE-2026-87858","Temporal Worker subprocess RCE","Temporal callback source header admin"],"first_seen":"2026-09-21T11:41:23.342Z","last_seen":"2026-09-21T13:26:39.796Z","objective":"Defensive public threat-intelligence record; see limitations and source references.","external_references":[{"source_name":"NVD CVE-2026-89139","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-89139"},{"source_name":"NVD CVE-2026-87858","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-87858"},{"source_name":"temporal PR 12021 auto-scaled-workers bump","url":"https://github.com/temporalio/temporal/pull/12021"},{"source_name":"temporal-auto-scaled-workers PR 129","url":"https://github.com/temporalio/temporal-auto-scaled-workers/pull/129"},{"source_name":"temporal PR 11965 callback source header opt-in","url":"https://github.com/temporalio/temporal/pull/11965"},{"source_name":"Temporal Server v1.31.3 release","url":"https://github.com/temporalio/temporal/releases/tag/v1.31.3"},{"source_name":"Temporal Server v1.30.7 release","url":"https://github.com/temporalio/temporal/releases/tag/v1.30.7"},{"source_name":"HOL Guard operator write-up","url":"https://hol.org/blog/cve-2026-89139-temporal-worker-subprocess-rce-callback-admin"}]}]}