CVE Explorer
CVE-2026-5724
The frontend gRPC server's streaming interceptor chain did not include the authorization interceptor. When a ClaimMapper and Authorizer are configured, unary RPCs enforce authentication and authorization, but the streaming AdminService/StreamWorkflowReplicationMessages endpoint accepted requests without credentials. This endpoint is registered on the same port as WorkflowService and cannot be disabled independently. An attacker with network access to the frontend port could open the replication
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"collectionURL":"https://github.com","defaultStatus":"unaffected","packageName":"temporal","product":"temporal","repo":"https://github.com/temporalio/temporal","vendor":"Temporal Technologies, Inc.","versions":[{"lessThan":"1.28.4","status":"affected","version":"1.24.0","versionType":"semver"},{"lessThan":"1.29.6","status":"affected","version":"1.29.0","versionType":"semver"},{"lessThan":"1.30.4","status":"affected","version":"1.30.0","versionType":"semver"},{"lessThan":"1.31.2","status":"affected","version":"1.31.0","versionType":"semver"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:b794b1fd7c443774bc6cc4c83d41ff17c0c9857a00c2b64ef60f8237b6c2bab1 · sha256:ba106144ad365ca0… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"Automatable":"NO","Recovery":"USER","Safety":"NEGLIGIBLE","attackComplexity":"LOW","attackRequirements":"PRESENT","attackVector":"NETWORK","baseScore":6.3,"baseSeverity":"MEDIUM","exploitMaturity":"NOT_DEFINED","privilegesRequired":"NONE","providerUrgency":"NOT_DEFINED","subAvailabilityImpact":"NONE","subConfidentialityImpact":"LOW","subIntegrityImpact":"NONE","userInteraction":"NONE","valueDensity":"NOT_DEFINED","vectorString":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:L/SC:L/SI:N/SA:N/S:N/AU:N/R:U/RE:L","version":"4.0","vulnAvailabilityImpact":"LOW","vulnConfidentialityImpac…
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:b794b1fd7c443774bc6cc4c83d41ff17c0c9857a00c2b64ef60f8237b6c2bab1 · sha256:ba106144ad365ca0… · /containers/cna/metrics/0/cvssV4_0
CWE assertions
1 source assertion{"cweId":"CWE-306","description":"CWE-306 Missing authentication for critical function","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:b794b1fd7c443774bc6cc4c83d41ff17c0c9857a00c2b64ef60f8237b6c2bab1 · sha256:ba106144ad365ca0… · /containers/cna/problemTypes/0/descriptions/0
Source references
4 source assertions{"tags":["patch"],"url":"https://github.com/temporalio/temporal/releases/tag/v1.28.4"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:b794b1fd7c443774bc6cc4c83d41ff17c0c9857a00c2b64ef60f8237b6c2bab1 · sha256:ba106144ad365ca0… · /containers/cna/references/2
{"tags":["patch"],"url":"https://github.com/temporalio/temporal/releases/tag/v1.29.6"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:b794b1fd7c443774bc6cc4c83d41ff17c0c9857a00c2b64ef60f8237b6c2bab1 · sha256:ba106144ad365ca0… · /containers/cna/references/0
{"tags":["patch"],"url":"https://github.com/temporalio/temporal/releases/tag/v1.30.4"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:b794b1fd7c443774bc6cc4c83d41ff17c0c9857a00c2b64ef60f8237b6c2bab1 · sha256:ba106144ad365ca0… · /containers/cna/references/1
{"tags":["patch"],"url":"https://github.com/temporalio/temporal/releases/tag/v1.31.2"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:b794b1fd7c443774bc6cc4c83d41ff17c0c9857a00c2b64ef60f8237b6c2bab1 · sha256:ba106144ad365ca0… · /containers/cna/references/3
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.