CVE-2026-5199Disclosure

LOWCVSS 2.3 · LOW

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A writer role user in an attacker-controlled namespace could signal, delete, and reset workflows or activities in a victim namespace on the same cluster. Exploitation requires the attacker to know or guess specific victim workflow ID(s) and, for signal operations, signal names. This was due to a bug introduced in Temporal Server v1.29.0 which inadvertently allowed an attacker to control the namespace name value instead of using the server's own trusted name value within the batch activity code. The batch activity validated the namespace ID but did not cross-check the namespace name against the worker's bound namespace, allowing the per-namespace worker's privileged credentials to operate on an arbitrary namespace. Exploitation requires a server configuration where internal components have cross-namespace authorization, such as deployment of the internal-frontend service or equivalent TLS-based authorization for internal identities. This vulnerability also impacted Temporal Cloud when the attacker and victim namespaces were on the same cell, with the same preconditions as self-hosted clusters.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-639

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked at 2 mentions on most recent observed day (2026-04-02)
  • 3 total mentions across 2 days

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-04-01: 1Mentions · 2026-04-02: 2Technical Details · 2026-04-01: 1Technical Details · 2026-04-02: 204-0104-02
Signal classification2 categories
Disclosure
266.7%
General
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-04-011
Disclosure1
2026-04-022
Disclosure1General1
Full discourse3 posts
  • Infoflowcloud@infoflowcloud
    General

    🚨*CVE* CVE-2026-5199 A writer role user in an attacker-controlled namespace could signal, delete, and reset workflows or activities in a victim namespace on the same cluster. Exploitation r… https://www.cve.org/CVERecord?id=CVE-2026-5199 ----- Traducción: CVE-2026-5199 Un … http://infoflow.cloud`

    Post summary

    The tweet references CVE‑2026‑5199, outlines role‑based cluster workflow control weaknesses, but provides no evidence of active exploitation, patch, or PoC.

    0000036
    65 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-5199 A writer role user in an attacker-controlled namespace could signal, delete, and reset workflows or activities in a victim namespace on the same cluster. Exploitation r… https://www.cve.org/CVERecord?id=CVE-2026-5199

    Post summary

    The passage announces CVE‑2026‑5199, describing a privilege escalation in Kubernetes that allows a writer‑role user in one namespace to control workflows in another namespace on the same cluster.

    00000200
    56.9K followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-5199 - Cross Namespace Access via Batch Operation Intel Report: https://ift.tt/W6VsZ7l

    Post summary

    An alert reports the CVE-2026-5199 vulnerability, which permits cross‑namespace access through batch operations, accompanied by a link to an Intel Report.

    0000042
    281 followersView on X

Explore more