Junglewise Threat Intelligence

CVE-2026-5724: Temporal Server missing authentication in gRPC streaming interceptor

CVE-2026-5724 · Severity: medium · CVSS 4 · Published 2026-04-10

Technologies: go.temporal.io/server (Go), Temporal Technologies, Inc. Temporal Server. Vendors: Go.

Executive brief

Temporal Server, a platform for managing durable business workflows, contains a security flaw where certain data replication requests do not require authentication. An attacker with network access to the server could potentially access sensitive workflow replication data without providing credentials. While exploiting this requires specific knowledge of the cluster's configuration, it could lead to unauthorized data exposure.

Technical details

The frontend gRPC server's streaming interceptor chain in Temporal Server was missing the authorization interceptor for specific endpoints. While unary RPCs correctly enforced authentication via ClaimMapper and Authorizer, the 'AdminService/StreamWorkflowReplicationMessages' endpoint remained accessible without credentials. This endpoint is hosted on the same port as the WorkflowService and cannot be disabled independently. An attacker with network access can initiate a replication stream; however, successful data exfiltration requires knowledge of the cluster ID and peer membership, as the history service performs secondary validation. Patches are available in versions 1.28.4, 1.29.6, 1.30.4, 1.31.2, and 1.32.0.

Affected products

  • Temporal Technologies, Inc. Temporal Server 1.24.0 to 1.28.3, 1.29.0 to 1.29.5, 1.30.0 to 1.30.3, 1.31.0 to 1.31.1

Timeline

  • 2026-04-10: disclosed
  • 2026-04-10: patched: Initial patches released for 1.28, 1.29, and 1.30 lines.
  • 2026-07-08: patched: Patch released for 1.31 line (v1.31.2).

References

Related threats