← Back to the live CVE advisory feed

CVE-2026-89139: Product identification pending

Severity
8.7 (HIGH)
Vendor
TEMPORAL
Patch status
Unknown
Published
2026-09-21T12:17:24.440
Modified
2026-09-21T16:17:26.203

Why it matters

High-severity vulnerability requiring prioritized review.

Recommended admin actions

  • Review and patch based on exposure, asset criticality, and business impact.

Technical summary

Temporal Server compiles a Worker Controller Instance module into its Worker Service, and that module registers a compute provider named subprocess whose function is to launch a worker by running a command on the machine hosting the Worker Service. The program name and the argument vector that provider executes are taken from the compute provider configuration supplied in the caller's request rather than from operator configuration. An authenticated caller holding only a write role in a single namespace can therefore configure a worker deployment version so that the Worker Service executes a command of the caller's choosing on its own host, under the account the server process runs as. Execution is immediate rather than deferred: the configuration handler invokes every provider using the invoke strategy directly after validating the submitted specification, so no scaling decision, task arrival, or unusual request sequence is required. Because the Worker Service process holds the persistence credentials for every namespace in the cluster and the cluster's TLS material, the consequence reaches beyond the caller's namespace to the cluster as a whole. The provider is present in the official temporal-server binaries and container images for the affected releases. The only control that can keep it unreachable is the compute provider allowlist, the per-namespace dynamic configuration setting workercontroller.compute_providers.enabled, and that control does not deny by default: its default value is an unset list, and the allowlist check is skipped entirely when the value is unset, so every registered compute provider is permitted, this one included. To determine whether a deployment is affected, check the following together. The deployed Temporal Server version is 1.31.0 or later and earlier than 1.31.3. The Worker Service is running, which it is in the default service set and therefore in a stock deployment. The effective per-namespace value of workercontroller.compute_providers.enabled is either unset or contains subprocess. And authorization is configured, meaning a real authorizer and claim mapper are in place; a deployment running with no authorizer already grants every caller unrestricted access to every namespace, so it has no namespace boundary for this to cross. Note that the separate per-namespace dynamic configuration setting workercontroller.enabled does not gate the affected path. It defaults to false, and a deployment that has never set it in any namespace is still affected, which was confirmed by running an affected release with no value for that setting present anywhere in dynamic configuration. To look for a compute configuration that is already attached, call DescribeWorkerDeploymentVersion for each worker deployment version in each namespace and check whether any scaling group's compute provider type is subprocess.

CVE data is sourced from NVD/CNA records and optional enrichment. Validate against the vendor advisory before taking production action.

VULNERABILITY PULSE

LAST UPDATED: SEP 22, 2026 08:00 AM UTC
281 RECORDS
SECURE FEED ACTIVE
AFFECTED PRODUCT ACTION
CVE-2026-77521
MaxKB PATCH
Reporter: SECURITY-ADVISORIES
10
CRITICAL
VIEW RECORD
CVE-2026-79920
ajenti PATCH
Reporter: SECURITY-ADVISORIES
9.9
CRITICAL
VIEW RECORD
CVE-2026-94301
Apache MINA
Reporter: SECURITY
9.8
CRITICAL
VIEW RECORD
CVE-2026-85751
Mailu PATCH
Reporter: SECURITY-ADVISORIES
9.8
CRITICAL
VIEW RECORD
CVE-2026-13355
Meta Box Frontend Submission
Reporter: SECURITY
9.8
CRITICAL
VIEW RECORD
CVE-2026-19658
Give Tributes
Reporter: SECURITY
9.8
CRITICAL
VIEW RECORD
CVE-2026-94571
Product identification pending PATCH
Reporter: CVE
9.4
CRITICAL
VIEW RECORD
CVE-2026-94572
Product identification pending PATCH
Reporter: CVE
9.4
CRITICAL
VIEW RECORD
CVE-2026-58491
warpgate PATCH
Reporter: SECURITY-ADVISORIES
9.3
CRITICAL
VIEW RECORD
CVE-2026-94424
MTT S80 Driver Package
Reporter: CNA
9.3
CRITICAL
VIEW RECORD
CVE-2026-94425
MTT S80 Driver Package
Reporter: CNA
9.3
CRITICAL
VIEW RECORD
CVE-2026-94493
PDV5701
Reporter: CNA
9.3
CRITICAL
VIEW RECORD
CVE-2026-61674
fluent-bit PATCH
Reporter: SECURITY-ADVISORIES
9.2
CRITICAL
VIEW RECORD
CVE-2025-12999
Eclipse Open VSX
Reporter: EMO
9.1
CRITICAL
VIEW RECORD
CVE-2026-86473
Apache Airflow PATCH
Reporter: SECURITY
9.1
CRITICAL
VIEW RECORD
CVE-2026-46649
joplin PATCH
Reporter: SECURITY-ADVISORIES
9.1
CRITICAL
VIEW RECORD
CVE-2026-79916
MaxKB PATCH
Reporter: SECURITY-ADVISORIES
9.1
CRITICAL
VIEW RECORD
CVE-2026-88807
Product identification pending PATCH
Reporter: MEISSNER
8.9
HIGH
VIEW RECORD
CVE-2026-55563
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
8.9
HIGH
VIEW RECORD
CVE-2026-92574
Confidential Compute Attestation
Reporter: SECALERT
8.8
HIGH
VIEW RECORD
CVE-2026-84285
Product identification pending
Reporter: 3DS.INFORMATION-SECURITY
8.8
HIGH
VIEW RECORD
CVE-2026-53940
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
8.8
HIGH
VIEW RECORD
CVE-2026-82412
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
8.8
HIGH
VIEW RECORD
CVE-2026-62371
kubeedge PATCH
Reporter: SECURITY-ADVISORIES
8.8
HIGH
VIEW RECORD
CVE-2026-63116
deepstream.io PATCH
Reporter: SECURITY-ADVISORIES
8.8
HIGH
VIEW RECORD
CVE-2026-84990
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
8.8
HIGH
VIEW RECORD
CVE-2026-62182
kubeedge PATCH
Reporter: SECURITY-ADVISORIES
8.8
HIGH
VIEW RECORD
CVE-2026-55159
luci-app-adblock-fast PATCH
Reporter: SECURITY-ADVISORIES
8.8
HIGH
VIEW RECORD
CVE-2026-55897
luci PATCH
Reporter: SECURITY-ADVISORIES
8.8
HIGH
VIEW RECORD
CVE-2026-88409
Product identification pending
Reporter: CVE
8.8
HIGH
VIEW RECORD
CVE-2026-92438
Ninja Forms
Reporter: CONTACT
8.8
HIGH
VIEW RECORD
CVE-2026-16651
Product identification pending
Reporter: SECURITY
8.7
HIGH
VIEW RECORD
CVE-2026-65651
Product identification pending
Reporter: SECURITY
8.7
HIGH
VIEW RECORD
CVE-2026-65652
Product identification pending
Reporter: SECURITY
8.7
HIGH
VIEW RECORD
CVE-2026-65653
Product identification pending
Reporter: SECURITY
8.7
HIGH
VIEW RECORD
CVE-2026-65654
Product identification pending
Reporter: SECURITY
8.7
HIGH
VIEW RECORD
CVE-2026-89139
Product identification pending
Reporter: SECURITY
8.7
HIGH
VIEW RECORD
CVE-2026-94381
MISP
Reporter: 5A6E4751-2F3F-4070-9419-94FB35B644E8
8.7
HIGH
VIEW RECORD
CVE-2026-94411
Product identification pending
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-94412
Product identification pending
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-94496
jshERP
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-94497
jshERP
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-94501
Product identification pending
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-61652
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
8.7
HIGH
VIEW RECORD
CVE-2026-94622
vllm
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-94623
Product identification pending
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-94624
Product identification pending
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-94626
vllm
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-94627
vllm
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-94383
MISP
Reporter: 5A6E4751-2F3F-4070-9419-94FB35B644E8
8.6
HIGH
VIEW RECORD
CVE-2025-71421
Product identification pending PATCH
Reporter: DISCLOSURE
8.6
HIGH
VIEW RECORD
CVE-2026-94403
iGameCenter
Reporter: CNA
8.5
HIGH
VIEW RECORD
CVE-2026-55071
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
8.4
HIGH
VIEW RECORD
CVE-2026-49811
Product identification pending PATCH
Reporter: SECURITY_ALERT
8.4
HIGH
VIEW RECORD
CVE-2026-94374
MISP
Reporter: 5A6E4751-2F3F-4070-9419-94FB35B644E8
8.3
HIGH
VIEW RECORD
CVE-2026-94401
MISP
Reporter: 5A6E4751-2F3F-4070-9419-94FB35B644E8
8.3
HIGH
VIEW RECORD
CVE-2026-94488
Product identification pending PATCH
Reporter: CVE
8.3
HIGH
VIEW RECORD
CVE-2026-55074
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
8.2
HIGH
VIEW RECORD
CVE-2026-61628
nginx-ignition PATCH
Reporter: SECURITY-ADVISORIES
8.1
HIGH
VIEW RECORD
CVE-2026-80110
Product identification pending
Reporter: SECALERT
8.1
HIGH
VIEW RECORD
CVE-2026-94184
Product identification pending
Reporter: SECALERT
8.1
HIGH
VIEW RECORD
CVE-2026-77560
tinyauth PATCH
Reporter: SECURITY-ADVISORIES
8.1
HIGH
VIEW RECORD
CVE-2026-83621
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
8.1
HIGH
VIEW RECORD
CVE-2026-48826
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
8.1
HIGH
VIEW RECORD
CVE-2026-48975
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
8.1
HIGH
VIEW RECORD
CVE-2026-48976
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
8.1
HIGH
VIEW RECORD
CVE-2026-62369
kubeedge PATCH
Reporter: SECURITY-ADVISORIES
8.1
HIGH
VIEW RECORD
CVE-2026-58269
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
8.1
HIGH
VIEW RECORD
CVE-2026-15801
Red Hat OpenShift Container Platform 4
Reporter: SECALERT
8
HIGH
VIEW RECORD
CVE-2026-65980
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
7.9
HIGH
VIEW RECORD
CVE-2026-55567
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
7.8
HIGH
VIEW RECORD
CVE-2026-17052
Product identification pending
Reporter: VULNERABILITIES
7.8
HIGH
VIEW RECORD
CVE-2026-49810
Product identification pending PATCH
Reporter: SECURITY_ALERT
7.8
HIGH
VIEW RECORD
CVE-2026-81469
Product identification pending PATCH
Reporter: SECURITY_ALERT
7.8
HIGH
VIEW RECORD
CVE-2026-76898
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
7.7
HIGH
VIEW RECORD
CVE-2026-63330
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
7.7
HIGH
VIEW RECORD
CVE-2026-55105
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
7.7
HIGH
VIEW RECORD
CVE-2026-59814
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
7.6
HIGH
VIEW RECORD
CVE-2026-47321
Apache MINA
Reporter: SECURITY
7.5
HIGH
VIEW RECORD
CVE-2026-91863
Product identification pending PATCH
Reporter: SECURITY
7.5
HIGH
VIEW RECORD
CVE-2026-91864
Product identification pending PATCH
Reporter: SECURITY
7.5
HIGH
VIEW RECORD
CVE-2026-91865
Product identification pending PATCH
Reporter: SECURITY
7.5
HIGH
VIEW RECORD
CVE-2026-91866
Product identification pending PATCH
Reporter: SECURITY
7.5
HIGH
VIEW RECORD
CVE-2026-88806
Product identification pending PATCH
Reporter: MEISSNER
7.5
HIGH
VIEW RECORD
CVE-2026-52741
gocd PATCH
Reporter: SECURITY-ADVISORIES
7.5
HIGH
VIEW RECORD
CVE-2026-61629
nginx-ignition PATCH
Reporter: SECURITY-ADVISORIES
7.5
HIGH
VIEW RECORD
CVE-2026-71543
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
7.5
HIGH
VIEW RECORD
CVE-2026-94449
Product identification pending
Reporter: SECALERT
7.5
HIGH
VIEW RECORD
CVE-2026-73512
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
7.5
HIGH
VIEW RECORD
CVE-2026-73513
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
7.5
HIGH
VIEW RECORD
CVE-2026-73547
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
7.5
HIGH
VIEW RECORD
CVE-2026-73548
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
7.5
HIGH
VIEW RECORD
CVE-2026-73550
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
7.5
HIGH
VIEW RECORD
CVE-2026-73552
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
7.5
HIGH
VIEW RECORD
CVE-2026-73553
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
7.5
HIGH
VIEW RECORD
CVE-2026-88406
Product identification pending
Reporter: CVE
7.5
HIGH
VIEW RECORD
CVE-2026-88407
Product identification pending
Reporter: CVE
7.5
HIGH
VIEW RECORD
CVE-2026-88411
Product identification pending
Reporter: CVE
7.5
HIGH
VIEW RECORD
CVE-2026-91827
Ninja Forms
Reporter: CONTACT
7.5
HIGH
VIEW RECORD
CVE-2026-75939
Product identification pending
Reporter: SECALERT
7.4
HIGH
VIEW RECORD

About the Vulnerability Pulse CVE Feed

The Vulnerability Pulse feed tracks live CVE advisories sourced from the National Vulnerability Database and vendor security disclosures. It is designed for SOC analysts, IT administrators, and security teams who need a fast, filterable view of current vulnerabilities without digging through raw NVD data.

How to Use the CVE Advisory Tracker

Use the severity filters to narrow results to Critical or High priority vulnerabilities. Filter by vendor to focus on software and hardware relevant to your environment. Export to CSV for reporting, ticketing, or patch prioritization workflows.

What Is a CVE Advisory?

A CVE (Common Vulnerabilities and Exposures) advisory is a public disclosure of a security vulnerability assigned a unique identifier by MITRE. Advisories include severity scores (CVSS), affected versions, and remediation guidance. Monitoring CVE advisories is a core function of vulnerability management programs and SOC operations.

CVE Analysis & Writeups

For in-depth analysis of specific vulnerabilities, visit the IT Knowledge Bases blog for CVE breakdowns, exploitation analysis, and remediation guidance written for security practitioners.