research.empiricalsecurity.com Critical CVE-2026-58138 in Orkes Conductor Exploited in the Wild
Article Content
- •CVE-2026-58138 allows unauthenticated remote code execution in Orkes Conductor.
- •Active exploitation confirmed since August 21, 2026, with significant attempts blocked.
- •Organizations must upgrade to Conductor version 3.30.2 or later to mitigate risks.
A critical vulnerability, CVE-2026-58138, in Orkes Conductor allows unauthenticated remote code execution. This flaw, affecting versions prior to 3.30.2, enables attackers to submit malicious JavaScript or Python expressions via the workflow API endpoint. Exploitation can invoke arbitrary system commands due to the GraalVM context configured with HostAccess.ALL, which disables the sandbox. The vulnerability was published on June 30, 2026, and proof-of-concept code was released shortly after. Active exploitation was confirmed starting August 21, 2026, with Fortinet blocking approximately 1,300 attempts in early September. Organizations using Conductor are advised to upgrade to version 3.30.2 or later and restrict access to their workflow API endpoints. The vulnerability has a CVSS score of 9.8, indicating its critical nature.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (3)
Following this threat?
Track Envoy and CVE-2026-58138 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Zero-Day Vulnerability in Cisco Secure Email Gateway Exploited On September 14, 2026, Cisco disclosed a critical SQL injection vulnerability (CVE-2026-76461) in its Secure Email Gateway, allowing unauthenticated remote attackers to execute arbitrary commands with root privileges. This vulnerability arises from insufficient validation in the email parsing logic. Cisco confirmed…