CVE-2026-5724 affects self-hosted Temporal installations running with ClaimMapper and Authorizer authentication configured. The vulnerability exists in the frontend gRPC server's streaming interceptor chain, which fails to include the authorization interceptor for the AdminService/StreamWorkflowReplicationMessages endpoint. This allows unauthenticated users to access a streaming endpoint that should require credentials, though exploitation requires network access to the frontend port and knowledge of cluster configuration details. The attack vector is network-based with low complexity, as an attacker only needs to initiate a connection to the exposed endpoint without authentication. However, the actual impact is constrained by validation controls in the history service, which verifies cluster IDs and peer membership before returning replication data. Data exfiltration is theoretically possible but depends on the attacker having advance knowledge of the cluster configuration and a correctly configured replication target. The vulnerability has a FAUCET Risk Score of 44.0 out of 100 and an EPSS score of 0.00038, indicating it ranks higher than approximately 0.11 percent of all CVEs in terms of exploitation likelihood. There is no indication of active exploitation, and the vulnerability does not appear on the Known Exploited Vulnerabilities list. Temporal Cloud is not affected, limiting the scope to organizations operating self-hosted instances.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Temporal Technologies, Inc. | Temporal | >= 1.24.0, < 1.28.4, >= 1.29.0, < 1.29.6, >= 1.30.0, < 1.30.4, >= 1.31.0, < 1.31.2CNA affecteddefault unaffected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:L/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:N/AU:N/R:U/V:X/RE:L/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.