Skip to content
Critical CVE-2026-58138 in Orkes Conductor Exploited in the Wild

Critical CVE-2026-58138 in Orkes Conductor Exploited in the Wild

First seen 18 Sep 2026, 11:26 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster September 18, 2026 at 15:58 UTC
  • CVE-2026-58138 allows unauthenticated remote code execution in Orkes Conductor.
  • Active exploitation confirmed since August 21, 2026, with significant attempts blocked.
  • Organizations must upgrade to Conductor version 3.30.2 or later to mitigate risks.

A critical vulnerability, CVE-2026-58138, in Orkes Conductor allows unauthenticated remote code execution. This flaw, affecting versions prior to 3.30.2, enables attackers to submit malicious JavaScript or Python expressions via the workflow API endpoint. Exploitation can invoke arbitrary system commands due to the GraalVM context configured with HostAccess.ALL, which disables the sandbox. The vulnerability was published on June 30, 2026, and proof-of-concept code was released shortly after. Active exploitation was confirmed starting August 21, 2026, with Fortinet blocking approximately 1,300 attempts in early September. Organizations using Conductor are advised to upgrade to version 3.30.2 or later and restrict access to their workflow API endpoints. The vulnerability has a CVSS score of 9.8, indicating its critical nature.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-06-30
CVE-2026-58138 published
A critical vulnerability in Orkes Conductor was disclosed, affecting versions before 3.30.2.
research.empiricalsecurity.com
2026-07-01
First public PoC released
Proof-of-concept code for exploiting CVE-2026-58138 became publicly available.
research.empiricalsecurity.com
2026-08-21
Active exploitation observed
Empirical Security confirmed in-the-wild exploitation of CVE-2026-58138.
research.empiricalsecurity.com
2026-09-08
Fortinet blocks exploitation attempts
Fortinet reported blocking approximately 1,300 exploitation attempts targeting CVE-2026-58138.
Feeds.Feedburner
2026-09-18
Organizations urged to patch
Security advisories recommend upgrading to Conductor version 3.30.2 or later to mitigate the vulnerability.
Feeds.Feedburner

More articles in this cluster (3)

Following this threat?

Track Envoy and CVE-2026-58138 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed