CVE-2026-89139 PUBLISHED

Temporal Server worker deployment compute provider executes a caller-supplied command on the Worker Service host

Assigner: Temporal
Reserved: 10.09.2026 Published: 21.09.2026 Updated: 21.09.2026

Temporal Server compiles a Worker Controller Instance module into its Worker Service, and that module registers a compute provider named subprocess whose function is to launch a worker by running a command on the machine hosting the Worker Service. The program name and the argument vector that provider executes are taken from the compute provider configuration supplied in the caller's request rather than from operator configuration. An authenticated caller holding only a write role in a single namespace can therefore configure a worker deployment version so that the Worker Service executes a command of the caller's choosing on its own host, under the account the server process runs as. Execution is immediate rather than deferred: the configuration handler invokes every provider using the invoke strategy directly after validating the submitted specification, so no scaling decision, task arrival, or unusual request sequence is required. Because the Worker Service process holds the persistence credentials for every namespace in the cluster and the cluster's TLS material, the consequence reaches beyond the caller's namespace to the cluster as a whole. The provider is present in the official temporal-server binaries and container images for the affected releases. The only control that can keep it unreachable is the compute provider allowlist, the per-namespace dynamic configuration setting workercontroller.compute_providers.enabled, and that control does not deny by default: its default value is an unset list, and the allowlist check is skipped entirely when the value is unset, so every registered compute provider is permitted, this one included. To determine whether a deployment is affected, check the following together. The deployed Temporal Server version is 1.31.0 or later and earlier than 1.31.3. The Worker Service is running, which it is in the default service set and therefore in a stock deployment. The effective per-namespace value of workercontroller.compute_providers.enabled is either unset or contains subprocess. And authorization is configured, meaning a real authorizer and claim mapper are in place; a deployment running with no authorizer already grants every caller unrestricted access to every namespace, so it has no namespace boundary for this to cross. Note that the separate per-namespace dynamic configuration setting workercontroller.enabled does not gate the affected path. It defaults to false, and a deployment that has never set it in any namespace is still affected, which was confirmed by running an affected release with no value for that setting present anywhere in dynamic configuration. To look for a compute configuration that is already attached, call DescribeWorkerDeploymentVersion for each worker deployment version in each namespace and check whether any scaling group's compute provider type is subprocess.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CVSS Score: 8.7

Product Status

Vendor Temporal Technologies, Inc.
Product Temporal Server
Versions Default: unaffected
  • affected from 1.31.0 to 1.31.3 (excl.)

Affected Configurations

Exploitation requires all of the following at once. The deployment runs an affected Temporal Server release with the Worker Service enabled, which is the default service set, so a stock deployment satisfies this. Authorization is configured through an authorizer and a claim mapper; without it every caller already holds unrestricted access to every namespace and there is no namespace boundary to cross. The caller holds a write role in some namespace, which is what the frontend requires to create a worker deployment version or to update a worker deployment version's compute configuration. A worker deployment is already registered in that namespace, because the create call updates an existing worker deployment rather than starting one; registering a worker deployment requires the same namespace write role the rest of the path already requires, so this adds a step without raising the privilege needed. No feature flag has to be enabled by the operator: system.enableDeploymentVersions defaults to true, the per-namespace Worker Controller component is enabled unconditionally, and the compute provider allowlist defaults to permitting every registered provider. The provider wraps the command it runs in the timeout utility, which must resolve on the host's PATH; the base image used for the official container images supplies it.

Workarounds

Set the per-namespace dynamic configuration setting workercontroller.compute_providers.enabled to an explicit list naming only the compute providers the deployment intends to permit, omitting subprocess. An explicit empty list denies every compute provider. Leaving the setting unset is what permits everything, because the allowlist check is skipped when no value is configured; giving the setting any explicit value, an empty list included, makes the check run and denies any provider absent from the list. The request is then rejected with InvalidArgument before the provider runs. This is dynamic configuration, so it takes effect without restarting the server and is available during an incident rather than only at a maintenance window. Verify the effective value for every namespace in scope, including any namespace-constrained entries that could override a cluster-wide value.

Solutions

Upgrade to Temporal Server 1.32.0 or 1.31.3. Both pin a Worker Controller Instance module revision whose compute provider allowlist denies by default instead of permitting every registered provider. Operators who cannot upgrade immediately can apply the workaround below, which closes the same path without waiting for a release. The 1.30 release line does not depend on the Worker Controller Instance module at all and is unaffected. Note that the change shipped in 1.32.0 and 1.31.3 makes the allowlist deny by default and does not change where the executed command comes from: for a compute provider an operator does deliberately add to the allowlist, the program name and argument vector still arrive in the caller's request.

Credits

  • Reported internally at Temporal Technologies, Inc. finder

References

Problem Types

  • CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') CWE
  • CWE-749: Exposed Dangerous Method or Function CWE
  • CWE-1188: Initialization of a Resource with an Insecure Default CWE

Impacts

  • Command execution on the host running the Temporal Worker Service, as the operating system account the server process runs under, reachable from an ordinary namespace write role. That process holds the persistence credentials for every namespace in the cluster as well as the cluster's TLS material, so the effect is cross-namespace and cluster-wide rather than confined to the caller's own namespace. In the official container image the server runs as an unprivileged account rather than root, which bounds host takeover but does not bound access to the credentials and key material the server process itself holds.