Critical Pre-Auth RCE in Orkes Conductor Workflow Platform Exploited in the Wild
AI Summary
A critical pre-authentication remote code execution (RCE) vulnerability, CVE-2026-58138, in Orkes Conductor Workflow Platform is being actively exploited in the wild. The flaw exists in versions prior to 3.30.2 and allows unauthenticated attackers to execute arbitrary OS commands by submitting malicious workflow definitions containing JavaScript or Python expressions to the Conductor API endpoint. Exploitation leverages unsandboxed GraalVM evaluators with unrestricted host access, enabling command execution via Java reflection or subprocess calls. Attack attempts have been observed globally, with significant activity originating from Germany, Hong Kong, Indonesia, the U.A.E., and India, and telemetry from multiple security firms confirming ongoing exploitation.
AI-extracted · verify before operational use