Executive brief
Temporal Server, a platform for managing durable business workflows, contains a security flaw where certain data replication requests do not require authentication. An attacker with network access to the server could potentially access sensitive workflow replication data without providing credentials. While exploiting this requires specific knowledge of the cluster's configuration, it could lead to unauthorized data exposure.
Technical details
The frontend gRPC server's streaming interceptor chain in Temporal Server was missing the authorization interceptor for specific endpoints. While unary RPCs correctly enforced authentication via ClaimMapper and Authorizer, the 'AdminService/StreamWorkflowReplicationMessages' endpoint remained accessible without credentials. This endpoint is hosted on the same port as the WorkflowService and cannot be disabled independently. An attacker with network access can initiate a replication stream; however, successful data exfiltration requires knowledge of the cluster ID and peer membership, as the history service performs secondary validation. Patches are available in versions 1.28.4, 1.29.6, 1.30.4, 1.31.2, and 1.32.0.
Affected products
- Temporal Technologies, Inc. Temporal Server 1.24.0 to 1.28.3, 1.29.0 to 1.29.5, 1.30.0 to 1.30.3, 1.31.0 to 1.31.1
Timeline
- 2026-04-10: disclosed
- 2026-04-10: patched: Initial patches released for 1.28, 1.29, and 1.30 lines.
- 2026-07-08: patched: Patch released for 1.31 line (v1.31.2).