hacker-news · Crawled Sep 19, 2026

Critical Pre-Auth RCE in Orkes Conductor Workflow Platform Exploited in the Wild

2 IoCs 1 CVEs
Read original article ↗

AI Summary

A critical pre-authentication remote code execution (RCE) vulnerability, CVE-2026-58138, in Orkes Conductor Workflow Platform is being actively exploited in the wild. The flaw exists in versions prior to 3.30.2 and allows unauthenticated attackers to execute arbitrary OS commands by submitting malicious workflow definitions containing JavaScript or Python expressions to the Conductor API endpoint. Exploitation leverages unsandboxed GraalVM evaluators with unrestricted host access, enabling command execution via Java reflection or subprocess calls. Attack attempts have been observed globally, with significant activity originating from Germany, Hong Kong, Indonesia, the U.A.E., and India, and telemetry from multiple security firms confirming ongoing exploitation.

AI-extracted · verify before operational use

Extracted Entities 1 found

Indicators of Compromise 2 extracted

Type Value Detail
IP 185[.]130[.]105[.]12 Details →
IP 45[.]145[.]211[.]88 Details →

MITRE ATT&CK TTPs 3 techniques