Critical Pre-Auth RCE in Orkes Conductor Workflow Platform Exploited in the Wild
Reported exploitedOrkes ConductorOur summary
Attackers are actively exploiting CVE-2026-58138, a pre-authentication remote code execution flaw in Orkes Conductor 3.21.21 before 3.30.2. Crafted workflow definitions can abuse unsandboxed JavaScript or Python evaluation to run operating-system commands as the Conductor process; organizations should upgrade to Conductor 3.30.2 or later and restrict access to workflow API endpoints.
Read at The Hacker News
The Hacker News publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.