CVE-2026-5724: Missing Authentication on Streaming gRPC Replication Endpoint

Published Apr 10, 2026
·
Updated

The frontend gRPC server's streaming interceptor chain did not include the authorization interceptor. When a ClaimMapper and Authorizer are configured, unary RPCs enforce authentication and authorization, but the streaming AdminService/StreamWorkflowReplicationMessages endpoint accepted requests without credentials. This endpoint is registered on the same port as WorkflowService and cannot be disabled independently. An attacker with network access to the frontend port could open the replication stream without authentication. Data exfiltration is possible, but  only when a configured replication target is correctly configured and the attacker has knowledge of the cluster configuration, as the history service validates cluster IDs and peer membership before returning replication data.

Temporal Cloud is not affected.

Other sources

The frontend gRPC server's streaming interceptor chain did not include the authorization interceptor. When a ClaimMapper and Authorizer are configured, unary RPCs enforce authentication and authorization, but the streaming AdminService/StreamWorkflowReplicationMessages endpoint accepted requests without credentials. This endpoint is registered on the same port as WorkflowService and cannot be disabled independently. An attacker with network access to the frontend port could open the replication stream without authentication. Data exfiltration is possible, but  only when a configured replication target is correctly configured and the attacker has knowledge of the cluster configuration, as the history service validates cluster IDs and peer membership before returning replication data.

The fix was applied per release line: it is present in 1.28.4, 1.29.6, 1.30.4, 1.31.2, and 1.32.0 and later releases on each line. Releases 1.31.0 and 1.31.1 do not contain the fix and are affected.

Temporal Cloud is not affected.

MITRE

Affected Software

4 affected componentsFixes available
Temporal Temporal Server
go/go.temporal.io/server>=1.30.0-143.0<1.30.4
1.30.4
go/go.temporal.io/server>=1.29.0-135.0<1.29.6
1.29.6
go/go.temporal.io/server<1.28.4
1.28.4

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade go/go.temporal.io/server to a version that resolves this vulnerability.

    Fixed in 1.30.4
  2. Upgrade

    Upgrade go/go.temporal.io/server to a version that resolves this vulnerability.

    Fixed in 1.29.6
  3. Upgrade

    Upgrade go/go.temporal.io/server to a version that resolves this vulnerability.

    Fixed in 1.28.4
  4. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Fixed in 1.31.2
  5. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Fixed in 1.32.0
  6. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Fixed in 1.30.4
  7. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Fixed in 1.29.6
  8. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Fixed in 1.28.4
  9. Configuration

    Update the frontend gRPC server streaming interceptor chain so the authorization interceptor is included for the streaming AdminService/StreamWorkflowReplicationMessages replication endpoint; the fix was that the streaming interceptor chain did not include the authorization interceptor.

    Frontend gRPC server (streaming interceptor chain) authorization interceptor inclusion for streaming AdminService/StreamWorkflowReplicationMessages endpoint = include authorization interceptor

Event History

Apr 10, 2026
CVE Published
via MITRE·09:06 PM
Data Sourced
via MITRE·09:06 PM
DescriptionWeakness
Data Sourced
via NVD·09:16 PM
DescriptionSeverityWeakness
Advisory Published
via GitHub·09:31 PM
Data Sourced
via GitHub·09:31 PM
DescriptionWeaknessAffected Software
Jan 26, 58293
Event
via FIRST·08:47 PM
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-5724?

CVE-2026-5724 has been rated as a medium severity vulnerability due to missing authentication on the streaming gRPC replication endpoint.

2

How do I fix CVE-2026-5724?

To fix CVE-2026-5724, you need to update the Temporal Server to version 1.30.4 or later, or to version 1.29.6, or to version 1.28.4.

3

What types of attacks does CVE-2026-5724 enable?

CVE-2026-5724 could allow unauthorized users to gain access to streaming data and perform actions without proper authentication.

4

Which versions of Temporal Server are affected by CVE-2026-5724?

CVE-2026-5724 affects versions of Temporal Server prior to 1.30.4, 1.29.6, and 1.28.4 depending on the installed version.

5

Is CVE-2026-5724 related to streaming RPCs in Temporal Server?

Yes, CVE-2026-5724 specifically relates to the missing authentication in the streaming gRPC replication endpoint of the Temporal Server.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203