Critical RCE Flaw CVE-2026-58138 in Orkes Conductor Exploited via Unauthenticated API
A critical vulnerability (CVE-2026-58138, CVSS 9.8) in Orkes Conductor OSS versions 3.21.21 through 3.30.1 allows unauthenticated remote attackers to execute OS commands by submitting malicious workflow definitions to an exposed Workflow API. The flaw stems from the API lacking authentication by default, enabling attackers to inject harmful JavaScript or Python expressions via task types such as INLINE, LAMBDA, DO_WHILE, or SWITCH, which are then executed through GraalVM with full host access. Empirical Security observed active exploitation in its telemetry, while Fortinet reportedly blocked around 1,300 attack attempts, though successful code execution has not been publicly confirmed. Successful exploitation could grant attackers root-level access within the Conductor container, potentially compromising connected data, credentials, microservices, and AI agents. Administrators are advised to upgrade to version 3.30.2 or later and restrict Workflow API access to internal networks with proper authentication and authorization controls.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.


Discussion (0)
Log in to join the discussion and vote.
Log in