CVE-2025-14986Disclosure

LOWCVSS 1.3 · LOW

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

When frontend.enableExecuteMultiOperation is enabled, the server can apply namespace-scoped validation and feature gates for the embedded StartWorkflowExecutionRequest using its Namespace field rather than the outer, authorized ExecuteMultiOperationRequest.Namespace. This allows a caller authorized for one namespace to bypass that namespace's limits/policies by setting the embedded start request's namespace to a different namespace. The workflow is still created in the outer (authorized) namespace; only validation/gating is performed under the wrong namespace context. This issue affects Temporal: from 1.24.0 through 1.29.1. Fixed in 1.27.4, 1.28.2, 1.29.2.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-863

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-02-07); latest day: 1
  • 4 total mentions across 3 days

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-02-06: 1Mentions · 2026-02-07: 2Mentions · 2026-02-17: 1Patch / Workaround · 2026-02-07: 2Technical Details · 2026-02-07: 202-0602-0702-17
Signal classification3 categories
Disclosure
250.0%
General
125.0%
Patch
125.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-02-061
General1
2026-02-072
Disclosure1Patch1
2026-02-171
Disclosure1
Full discourse4 posts
  • Angsuman Chakraborty ✪@angsuman
    Disclosure

    Masked namespace vulnerability in Temporal https://depthfirst.com/post/the-masked-namespace-vulnerability-in-temporal-cve-2025-14986

    Post summary

    The post announces a new namespace-related vulnerability in Temporal (CVE‑2025‑14986) with no additional details, remediation, or evidence of active exploitation.

    0000033
    7.5K followersView on X
  • Tech Daily 24/7@techdaily24
    Patch

    Critical vulnerability (CVE-2025-14986) found in Temporal's Go server! This flaw allows unauthorized cross-namespace actions, bypassing security policies. Update your systems to prevent potential breaches. #TemporalSecurity #CVE https://t.co/CSDufS5FPU

    Post summary

    A critical CVE-2025-14986 in Temporal’s Go server enables unauthorized cross-namespace actions; users are urged to update their systems to mitigate potential breaches.

    0000054
    60 followersView on X
  • topickapp (IT技術系ニュースサイト)@topickapp_com
    Disclosure

    https://depthfirst.com/post/the-masked-namespace-vulnerability-in-temporal-cve-2025-14986 TemporalのExecuteMultiOperationエンドポイントで「Masked Namespace」脆弱性(CVE-2025-14986)を発見。 この脆弱性は、認証された名前空間とは異なる名前空間でポリシー評価をさせることを可能にしました。 Temporal v1.27で修正済みです。

    Post summary

    The post reports the discovery of the Masked Namespace vulnerability (CVE-2025-14986) in Temporal's ExecuteMultiOperation endpoint, explains how it enables policy evaluation in an unauthorized namespace, and notes that it was fixed in version 1.27.

    0000070
    441 followersView on X
  • Hacker News 20@betterhn20
    General

    Masked namespace vulnerability in Temporal https://depthfirst.com/post/the-masked-namespace-vulnerability-in-temporal-cve-2025-14986 (https://news.ycombinator.com/item?id=46917477)

    Post summary

    The post references CVE-2025-14986 for a masked namespace vulnerability in Temporal but offers no further exploitation details, patch information, or technical specifics.

    0000099
    2.6K followersView on X

Explore more