Critical Pre-Auth RCE in Orkes Conductor Workflow Platform Exploited in the Wild
Orkes Conductor 3.21.21 before 3.30.2 contains a critical unauthenticated remote code execution vulnerability exploited in the wild.
Intelligence analysis by Qwen 2.5 (3B)

Critical vulnerability in Orkes Conductor exploited, leading to remote code execution. Fortinet and Previdian report increased attack attempts.
Orkes Conductor has a big security hole that lets bad guys run their own code on your computer without you knowing. They can do things like open doors or take over your computer.
Analysis
{"heading_1":"Orkes Conductor Vulnerability Details","subheading_1":"CVE-2026-58138","content_1":"CVE-2026-58138 is a critical vulnerability in Orkes Conductor 3.21.21 before 3.30.2, allowing remote attackers to execute arbitrary OS commands via malicious workflow definitions.","subheading_2":"Vulnerability Description","content_2":"The vulnerability arises from unauthenticated remote code execution, enabling attackers to exploit unsandboxed GraalVM evaluators with unrestricted host access.","subheading_3":"Attack Vector and Impact","content_3":"Attackers can exploit the vulnerability by submitting crafted workflow definitions containing JavaScript or Python expressions to the Conductor workflow API, leading to arbitrary command execution with Conductor process privileges."}
Key points
- CVE-2026-58138 is a critical vulnerability in Orkes Conductor 3.21.21 before 3.30.2.
- Attackers can exploit the vulnerability by submitting crafted workflow definitions containing malicious JavaScript or Python expressions.
- Immediate upgrades to Orkes Conductor 3.30.2 or later can prevent attacks.
- Organizations should restrict external access to the workflow API and monitor for suspicious activity.
- Fortinet and Previdian have observed increased attack attempts since the vulnerability was reported.
Immediate upgrades to Orkes Conductor 3.30.2 or later can prevent attacks. Organizations should monitor for suspicious activity and restrict access to the workflow API.
If immediate upgrades are not possible, organizations should restrict external access to the workflow API and monitor for suspicious activity.


