CVE-2026-5199 affects Temporal Server v1.29.0 and later, allowing a writer role user in an attacker-controlled namespace to signal, delete, or reset workflows and activities in a victim namespace on the same cluster. This vulnerability arises from a bug that permitted attackers to control the namespace name value during batch activity operations, bypassing cross-namespace validation. Exploitation requires high complexity, necessitating knowledge of victim workflow IDs and specific server configurations enabling cross-namespace authorization for internal components. The potential impact is limited to low integrity and availability of affected workflows, resulting in a CVSS score of 2.3 (LOW). There is currently no evidence of active exploitation, public exploit code, or significant community discussion regarding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Temporal Technologies, Inc. | Temporal | >= 1.29.0, < 1.29.5, >= 1.30.0, < 1.30.3CNA affecteddefault unaffected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:N/AU:Y/R:U/V:X/RE:M/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.