Critical Pre-Auth RCE in Orkes Conductor Workflow Platform Exploited in the Wild
ID: de785ae4-7eb0-5b4c-8e8b-dc6ac4667236
STIX ID: report--de785ae4-7eb0-5b4c-8e8b-dc6ac4667236
Feed Name: The Hacker News
A critical unauthenticated remote code execution vulnerability (CVE-2026-58138, CVSS v3.1=9.8/v4=9.3) in Orkes Conductor (versions 3.21.21 before 3.30.2) is being actively exploited by submitting malicious inline workflow definitions containing JavaScript or Python to the workflow API, allowing attackers to execute arbitrary OS commands via unsandboxed GraalVM evaluators; Fortinet and other vendors have observed and blocked thousands of attempts and recommend immediate patching or network restrictions.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
