Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.3

CVE-2026-96770: Temporal s2s-proxy allows unauthorized connections with self-signed certificates

CVE-2026-96770 · published 5 days ago
Summary

The s2s-proxy component of Temporal can accept a client certificate without checking if it was issued by a trusted authority. This means an attacker could use a self‑made certificate to connect to the proxy and perform actions it is allowed to do, even without any valid credentials. Update to the latest version of s2s-proxy or change the configuration to require proper certificate verification.

What to do

The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.

Affected software
VendorProductAffected versions
temporal technologies, inc. s2s-proxy <= 0.2.2
Original advisory text
s2s-proxy accepts untrusted client certificates
All published s2s-proxy versions through 0.2.2 are affected. In versions 0.1.16 through 0.2.2, TLS server listeners use Go's RequireAnyClientCert mode when skipCAVerification is false. This mode checks that the client holds the certificate's private key but does not verify the certificate against the configured CA. An attacker can therefore use a self-signed certificate and key to establish a TLS and yamux connection, then invoke RPCs allowed by the proxy's configuration and Temporal credentials. No certificate or private key trusted by the deployment, and no Temporal credential, is required.
Severity
9.3 Critical
CVSS 4.0: 9.3 (NVD)
Exploitation
EPSS <1%
Type
CWE-296Improper Following of a Certificate's Chain of Trust
Timeline
Published23 Sep 2026
Updated27 Sep 2026
First seen23 Sep 2026
Sources
CVE-2026-96770 · MITRE
Track software like this
Free during beta