logo

Critical Pre-Auth RCE in Orkes Conductor Workflow Platform Exploited in the Wild

ID: de785ae4-7eb0-5b4c-8e8b-dc6ac4667236

STIX ID: report--de785ae4-7eb0-5b4c-8e8b-dc6ac4667236

Feed Name: The Hacker News

Threat Score
88/100

Date Published: 2026-09-19

Date Updated: 2026-09-19

Author: [email protected] (The Hacker News)

...
...

A critical unauthenticated remote code execution vulnerability (CVE-2026-58138, CVSS v3.1=9.8/v4=9.3) in Orkes Conductor (versions 3.21.21 before 3.30.2) is being actively exploited by submitting malicious inline workflow definitions containing JavaScript or Python to the workflow API, allowing attackers to execute arbitrary OS commands via unsandboxed GraalVM evaluators; Fortinet and other vendors have observed and blocked thousands of attempts and recommend immediate patching or network restrictions.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.