Executive brief
Temporal has a namespace policy bypass allowing requests to be authorized for incorrect contexts in go.temporal.io/server
Affected products
- Go go.temporal.io/server
Junglewise Threat Intelligence
CVE-2025-14986 · Severity: medium · CVSS 4 · Published 2026-01-12
Technologies: go.temporal.io/server (Go). Vendors: Go.
Temporal has a namespace policy bypass allowing requests to be authorized for incorrect contexts in go.temporal.io/server