HomeSecurityOrkes Conductor: Critical vulnerability CVE-2026-58138 under active exploitation

Orkes Conductor: Critical vulnerability CVE-2026-58138 under active exploitation

A critical vulnerability in Orkes Conductor allows remote, unauthenticated attackers to execute arbitrary commands on systems running the platform. The vulnerability, identified as CVE-2026-58138, has a CVSS 3.1 score of 9.8 and a CVSS 4.0 score of 9.3.

Orkes Conductor workflow API security

The issue affects versions 3.21.21 through 3.30.2 and is in the way expressions are evaluated within workflows. According to the CVE Record, an attacker can submit a specially crafted workflow definition to the API before a connection is required.

See also: WP Photo Album Plus: Critical RCE vulnerability via ImageMagick

Orkes Conductor: what the vulnerability reveals

The platform uses GraalVM to execute JavaScript or Python in INLINE, LAMBDA, DO_WHILE , and SWITCH. In vulnerable installations, the evaluator was configured with HostAccess.ALL or allowAllAccess(true), options that effectively remove the boundaries of the isolation environment.

Thus, malicious expressions can use Java reflection or direct process calls to execute operating system commands. The problem is made worse because the open source server does not enforce authentication by default, leaving the streaming API exposed when no additional layer of protection is in place.

Fortinet a FortiRecon score of 90/100. The company clarifies that the CVE has not yet been added to the CISA KEV list and is not, so far, attributed to a ransomware group or APT.

Remote code execution in Orkes Conductor

The picture of activity is even more worrying. SecurityWeek reports that proof-of-concept code was published in early August, and that Empirical Security detected real-world attacks on August 21. Fortinet blocked about 1,300 attempts between September 8 and 9, indicating that the report is not theoretical.

The attack does not require a compromised account, user interaction, or special preparation. All that is required is network access to an installation that accepts requests to the workflow API, for the attacker to register a malicious flow and request its execution. The commands are executed with the privileges of the Conductor process, which in many default installations may be excessively high.

Empirical Security notes that version 3.30.2 is the full fix, while previous versions 3.30.0 and 3.30.1 were based on a partial blocklist. For this reason, organizations should not stop at an interim upgrade, but confirm the exact version in container images, Helm charts, and production machines.

See also: SiYuan 3.8.4: Stored XSS and two serious vulnerabilities

Who is at risk and what can they do?

Organizations using self-managed installations of Orkes Conductor or the related Conductor OSS project for automation, microservice orchestration, and AI workflows are at risk. If the server is running with elevated privileges, the breach could extend to credentials and systems accessible by the flows.

The full fix is ​​in version 3.30.2, which was released on June 3, as documented in the official release notes. Versions 3.30.0 and 3.30.1 contained only a partial block and should not be considered a sufficient solution.

The SecNews technical team recommends an immediate upgrade to 3.30.2 or later, restricting access to /api/metadata/workflow and /api/workflow , and removing the service from the public Internet. Where the upgrade is delayed, a reverse server with mandatory authentication, strict firewall rules, and checking for suspicious flow submissions is needed.

See also: CVE-2026-53266: Critical vulnerability in Linux Kernel's ebtables SNAT

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

The Orkes Conductor report should be evaluated against the actual network, not just the presence of a firewall. Security teams need to check which operators can reach the service, whether there are unknown workflows, and whether requests to specific APIs were recorded. At the same time, searching for processes started by Conductor can reveal attempts to execute commands.

In installations where Orkes Conductor connects to databases, messaging systems, or AI tools, administrators should consider lateral movement possible until the audit is complete. Rotating secrets and credentials after the upgrade reduces the risk of prolonged access.

Orkes Conductor installation protection

Finally, administrators should review logs for unexpected workflow creations or executions and check whether the Conductor process had access to secrets, queues, or internal services. The upgrade closes the gap, but a review of exposure and permissions is necessary after installation.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS