CVE-2025-14986 - CVE House
Back to Database
Status published Low CVE-2025-14986

ExecuteMultiOperation Namespace Policy Bypass

Vulnerability Description

When frontend.enableExecuteMultiOperation is enabled, the server can apply namespace-scoped validation and feature gates for the embedded StartWorkflowExecutionRequest using its Namespace field rather than the outer, authorized ExecuteMultiOperationRequest.Namespace. This allows a caller authorized for one namespace to bypass that namespace's limits/policies by setting the embedded start request's namespace to a different namespace. The workflow is still created in the outer (authorized) namespace; only validation/gating is performed under the wrong namespace context. This issue affects Temporal: from 1.24.0 through 1.29.1. Fixed in 1.27.4, 1.28.2, 1.29.2.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-14986

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

Temporal
Vulnerable Versions:
1.24.0

Timeline

Official Publish: December 30th, 2025
Last Modified: January 2nd, 2026
Added to House: July 22nd, 2026

CVSS Vectors

Weaknesses (CWE)