Threats Tagged 'cve-2026-5724'
View all threats tagged with 'cve-2026-5724'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cve-2026-5724'
Click on any threat for detailed analysis and mitigation recommendations
Temporal-server version 1.29.7-r2 addresses multiple security vulnerabilities including CVE-2026-5724. The update fixes seven vulnerabilities in total, improving the security posture of the software. The affected versions include 1.31.1-r4 and all versions prior to 1.29.7-r2. No CVSS score is provided for CVE-2026-5724, but the severity is assessed as medium. There are no known exploits in the wild for this vulnerability at this time. Join the discussion | GCVE Database | 09/01/2026, 11:17:16 UTC Added: 08/14/2026, 16:36:54 UTC |
Temporal-server version 1.31.1-r5 addresses nine security vulnerabilities, including CVE-2026-5724. This release provides important security fixes to mitigate these issues. No CVSS score or detailed technical information about the vulnerabilities is provided. There are no known exploits in the wild at this time. The package is not a cloud service, so remediation requires updating to the fixed version. Join the discussion | GCVE Database | 08/13/2026, 12:10:09 UTC Added: 08/14/2026, 16:36:54 UTC |
0 The frontend gRPC server's streaming interceptor chain did not include the authorization interceptor. When a ClaimMapper and Authorizer are configured, unary RPCs enforce authentication and authorization, but the streaming AdminService/StreamWorkflowReplicationMessages endpoint accepted requests without credentials. This endpoint is registered on the same port as WorkflowService and cannot be disabled independently. An attacker with network access to the frontend port could open the replication stream without authentication. Data exfiltration is possible, but only when a configured replication target is correctly configured and the attacker has knowledge of the cluster configuration, as the history service validates cluster IDs and peer membership before returning replication data. The fix was applied per release line: it is present in 1.28.4, 1.29.6, 1.30.4, 1.31.2, and 1.32.0 and later releases on each line. Releases 1.31.0 and 1.31.1 do not contain the fix and are affected. Temporal Cloud is not affected. Join the discussion | CVE Database V5 | 04/10/2026, 21:06:31 UTC Added: 04/10/2026, 21:20:48 UTC |
Showing 1 to 3 of 3 results