Temporal Technologies Inc. maintains a workflow-orchestration platform that is narrowly scoped in product range but serves as infrastructure for distributed task execution and state management in enterprise applications. Its observed vulnerability signal centers on authorization and secure-defaults issues, reflecting the access-control and configuration-driven security model inherent to a centralized workflow coordinator. Current severity, exploitation, and CVE counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Temporal Technologies Inc. over time
Of all the CVEs published by Temporal Technologies Inc. as a CNA, 33.3% affect products that Temporal Technologies Inc. develops as a vendor.
Of all the CVEs published that affect products developed by Temporal Technologies Inc., 100.0% are self-published by Temporal Technologies Inc. as a CNA.
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-14987MEDIUM When system.enableCrossNamespaceCommands is enabled (on by default), the Temporal server permits certain workflow task commands (e.g. StartChildWorkflowExecution, SignalExternalWor | Dec 30, 2025 | 5.3 | 19 | NO | NO |
Insecure defaults in open-source Temporal Server before version 1.20 on all platforms allows an attacker to craft a task token with access to a namespace other than the one specifi | Jun 30, 2023 | 3.6 | 17 | NO | NO |
When frontend.enableExecuteMultiOperation is enabled, the server can apply namespace-scoped validation and feature gates for the embedded StartWorkflowExecutionRequest using its Na | Dec 30, 2025 | 1.3 | 15 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Temporal Technologies Inc..
Media articles that mention a CVE ID that affects a product developed by Temporal Technologies Inc. — matched by CVE ID, not by vendor name.