Today's cybersecurity headlines are brought to you by ThreatPerspective


Ethical Hacking News

Critical Pre-Auth RCE Vulnerability in Orkes Conductor Workflow Platform: A Growing Threat Landscape




A critical pre-authentication remote code execution (RCE) vulnerability in the Orkes Conductor workflow platform has been actively exploited in the wild, posing significant risks to organizations that utilize the platform. To mitigate this threat, organizations are advised to upgrade to version 3.30.2 or later, restrict external access to Conductor workflow API endpoints, and monitor for suspicious workflow submissions. The emergence of this vulnerability highlights the importance of prioritizing vulnerability management and patching, as well as staying vigilant in the face of emerging threats. Stay ahead of the threats by reading the full article and following the latest updates on cybersecurity news and alerts.

  • The Orkes Conductor workflow platform has a critical pre-authentication remote code execution (RCE) vulnerability (CVE-2026-58138) that has been actively exploited in the wild.
  • Fortinet has observed a notable increase in attack attempts targeting Orkes Conductor servers due to the vulnerability's high CVSS score of 9.8.
  • The vulnerability arises from an unauthenticated RCE vulnerability in versions 3.21.21 to 3.30.2, allowing remote attackers to execute arbitrary OS commands.
  • Organizations using Orkes Conductor are advised to upgrade to version 3.30.2 or later, restrict external access, and monitor for suspicious activity.
  • The vulnerability highlights the importance of maintaining robust security measures and staying vigilant in the face of emerging threats.



  • The cybersecurity landscape has witnessed a recent surge in the emergence of a critical pre-authentication remote code execution (RCE) vulnerability in the Orkes Conductor workflow platform. This vulnerability, identified as CVE-2026-58138, has been actively exploited in the wild by malicious actors, posing significant risks to organizations that utilize the platform.

    According to the latest threat intelligence reports, Fortinet has observed a notable increase in the number of attack attempts targeting Orkes Conductor servers susceptible to this vulnerability. In a recent outbreak alert, the company disclosed that it had blocked 1,290 attack attempts within a span of 24 hours, representing a 132% increase in daily activity. This surge in activity is attributed to the vulnerability's CVSS score, which stands at 9.8/CVSS v4 score: 9.3, indicating a high level of severity and potential impact.

    The vulnerability in question arises from an unauthenticated remote code execution vulnerability in the Orkes Conductor 3.21.21 before 3.30.2 versions. This allows remote attackers to execute arbitrary OS commands by submitting inline workflow definitions containing malicious JavaScript or Python expressions to the workflow API endpoint prior to authentication. The vulnerability is further exacerbated by the use of unsandboxed GraalVM evaluators configured with HostAccess.ALL or allowAllAccess(true) through INLINE, LAMBDA, DO_WHILE, and SWITCH task types, which enables attackers to invoke arbitrary system commands via Java reflection or direct subprocess calls.

    As a result, organizations that utilize the Orkes Conductor platform are advised to upgrade to version 3.30.2 or later, which addresses the vulnerability. In the absence of immediate patching, it is recommended to restrict external access to Conductor workflow API endpoints, place Conductor instances behind appropriate network access controls, and monitor for suspicious workflow submissions and unexpected command execution.

    The scope of this vulnerability extends beyond the Orkes Conductor platform, as it highlights the importance of maintaining robust security measures in place. The rise of such vulnerabilities underscores the need for organizations to prioritize vulnerability management and patching, as well as the importance of staying vigilant in the face of emerging threats.

    In conclusion, the critical pre-authentication RCE vulnerability in the Orkes Conductor workflow platform serves as a stark reminder of the evolving threat landscape. As organizations continue to navigate the complexities of modern cybersecurity, it is essential to remain proactive in identifying and addressing vulnerabilities, ensuring the integrity and security of critical systems.



    Related Information:
  • https://www.ethicalhackingnews.com/articles/Critical-Pre-Auth-RCE-Vulnerability-in-Orkes-Conductor-Workflow-Platform-A-Growing-Threat-Landscape-ehn.shtml

  • https://thehackernews.com/2026/09/critical-pre-auth-rce-in-orkes.html

  • https://nvd.nist.gov/vuln/detail/CVE-2026-58138

  • https://www.cvedetails.com/cve/CVE-2026-58138/


  • Published: Sat Sep 19 03:59:37 2026 by llama3.2 3B Q4_K_M













    © Ethical Hacking News . All rights reserved.

    Privacy | Terms of Use | Contact Us