CVE-2026-58138
CVSS 9.8 CRITICAL: orkes Conductor 3.21.21 before 3.30.2 contains an unauthenticated remote code execution vulnerability that allows… EPSS 9% (95th percentile).
Vulnerabilities · 2 days ago
Empirical Security says attackers have been using CVE-2026-58138 against Orkes Conductor since August, and Fortinet blocked about 1,300 exploitation attempts on September 8-9. The flaw is a critical remote code execution bug in Conductor's workflow API, which Orkes patched in version 3.30.2.
The issue sits in inline workflow evaluators for JavaScript and Python. Conductor runs that user-supplied code in a GraalVM context with HostAccess.ALL, which removes the sandbox and lets a hostile workflow reach OS commands as the Conductor process, often with root privileges. Because the API can be left open and requires no login by default, a single unauthenticated request can register and start the workflow.
For operators, the exposure is not just the bug but the reachable workflow endpoint: if it is internet-facing, the orchestration layer itself becomes a code-execution surface. Even after patching, any deployment that kept the API open should be treated as carrying the same trust problem until that entry point is no longer reachable.
CVSS 9.8 CRITICAL: orkes Conductor 3.21.21 before 3.30.2 contains an unauthenticated remote code execution vulnerability that allows… EPSS 9% (95th percentile).
2 sources covering this story
Critical Pre-Auth RCE in Orkes Conductor Workflow Platform Exploited in the Wild
Attackers are exploiting CVE-2026-58138 in Orkes Conductor, an unauthenticated RCE fixed in version 3.30.2.
Critical Orkes Conductor Vulnerability Exploited in Attacks
CVE-2026-58138 is an unauthenticated remote code execution vulnerability that attackers can exploit via inline workflow definitions.
Part of the PlainSec briefing for 2026-09-21