{"id":3004,"date":"2026-09-19T09:13:24","date_gmt":"2026-09-19T09:13:24","guid":{"rendered":"https:\/\/thedigitalfortress.us\/?p=3004"},"modified":"2026-09-19T09:13:24","modified_gmt":"2026-09-19T09:13:24","slug":"critical-pre-auth-rce-in-orkes-conductor-workflow-platform-exploited-in-the-wild","status":"publish","type":"post","link":"https:\/\/thedigitalfortress.us\/?p=3004","title":{"rendered":"Critical Pre-Auth RCE in Orkes Conductor Workflow Platform Exploited in the Wild"},"content":{"rendered":"<div>\n<p><span class=\"p-author\"><i class=\"icon-font icon-user\">\ue804<\/i><span class=\"author\">Ravie Lakshmanan<\/span><i class=\"icon-font icon-calendar\">\ue802<\/i><span class=\"author\">Sep 19, 2026<\/span><\/span><span class=\"p-tags\">Vulnerability \/ Web Security<\/span><\/p>\n<\/div>\n<div id=\"articlebody\">\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjL-YeIVFaRBKvtwQKBxAilhKMaZP_x6L979d8JL60W3AEHy9o2sfL_dMrJWy_sPIV70oIbP6DYe2KVhHh-mwbB4zBvrV_jEgdRiuc_IzNyyPSfUAOGvAp7J7JO06OWUWjSwuqpU4JJ_kNy0vtW1D9_gEtQNNVmWiYzRTpYMwhe-J3Bvve3EHrAp81Wht4L\/s1700-nu-rw-lo-l85-e365\/orkes.jpg\" style=\"display: block;  text-align: center; clear: left; float: left;\"><\/a><\/div>\n<p>A critical vulnerability impacting Orkes Conductor is being actively exploited in the wild, according to Fortinet.<\/p>\n<p>The vulnerability in question is <strong><a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/cve-2026-58138\" target=\"_blank\">CVE-2026-58138<\/a><\/strong> (CVSS v3.1 score: 9.8\/CVSS v4 score: 9.3), which relates to a case of unauthenticated remote code execution.<\/p>\n<p>\u00abOrkes Conductor 3.21.21 before 3.30.2 contains an unauthenticated remote code execution vulnerability that allows remote attackers to execute arbitrary OS commands by submitting inline workflow definitions containing malicious JavaScript or Python expressions to the workflow API endpoint prior to authentication,\u00bb a description of the flaw on the NIST National Vulnerability Database (NVD) reads.<\/p>\n<p>\u00abAttackers can exploit unsandboxed GraalVM evaluators configured with HostAccess.ALL or allowAllAccess(true) through INLINE, LAMBDA, DO_WHILE, and SWITCH task types to invoke arbitrary system commands via Java reflection or direct subprocess calls.\u00bb<\/p>\n<p>In an outbreak alert <a href=\"https:\/\/www.fortiguard.com\/outbreak-alert\/orkes-conductor-rce\" target=\"_blank\">issued<\/a> this week, Fortinet said it has observed attackers actively targeting Orkes Conductor servers susceptible to CVE-2026-58138 by submitting crafted workflow definitions containing JavaScript or Python expressions to the Conductor workflow API.<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/trust-world-update-d\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhYq3TvePXpW0JIC7fXyv7A1W8KQqmb-AZqza2EuPyT0k8Nm5CwHYHISFLKXSKIAyR8JRtqEFQ4zx5jADiAkZKQ08nRWG1jCRV5YAbhKua7WaDdH1L6wsI-xOkoV4brlMfK44UwU-4Q1xqWg0uNN7sZkMCzci4RXYgWMNPHTtuKua7OR4oCbmxE10u0yKnR\/s728-nu-rw-lo-l85-e365\/tl-d.jpg\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>\u00abBecause vulnerable evaluators can be configured with unrestricted host access, the attacker can escape the intended scripting environment and execute arbitrary operating system commands with the privileges of the Conductor process,\u00bb Fortinet said.<\/p>\n<p>As of September 9, 2026, the company <a href=\"https:\/\/www.fortiguard.com\/threat-signal-report\/6527\/orkes-conductor-evaluator-remote-code-execution\" target=\"_blank\">said<\/a> it had blocked 1,290 attack attempts within a span of 24 hours, representing a 132% increase in daily activity. Nearly 7,000 attempts were blocked between September 2 and 9, 2026. The majority of the attack activity is said to have originated from Germany, Hong Kong, Indonesia, the U.A.E., and India.<\/p>\n<p>Telemetry data from Previdian <a href=\"https:\/\/previdian.com\/CVE-2026-58138#telemetry\" target=\"_blank\">shows<\/a> three exploitation attempts against its honeypots since July 24, 2026, from two unique IP addresses in France and the U.S. Similarly, Empirical Security <a href=\"https:\/\/research.empiricalsecurity.com\/research\/september-2026-cve-of-the-month\" target=\"_blank\">noted<\/a> that it detected in-the-wild exploitation as recently as August 21, 2026.<\/p>\n<p>Organizations using affected versions are advised to upgrade to <a href=\"https:\/\/github.com\/conductor-oss\/conductor\/releases\/tag\/v3.30.2\" target=\"_blank\">Conductor 3.30.2<\/a> or later, which addresses the vulnerability. If immediate patching is not an option, it&#8217;s recommended to restrict external access to Conductor workflow API endpoints, place Conductor instances behind appropriate network access controls, and monitor for suspicious workflow submissions and unexpected command execution.<\/p>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>\ue804Ravie Lakshmanan\ue802Sep 19, 2026Vulnerability \/ Web Security A critical vulnerability impacting Orkes Conductor is being actively exploited in the wild, according to Fortinet. The vulnerability in question is CVE-2026-58138 (CVSS&hellip;<\/p>\n","protected":false},"author":1,"featured_media":3005,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[3466,58,128,3465,527,1040,316,656,2741],"class_list":["post-3004","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-conductor","tag-critical","tag-exploited","tag-orkes","tag-platform","tag-preauth","tag-rce","tag-wild","tag-workflow"],"_links":{"self":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/3004","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=3004"}],"version-history":[{"count":0,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/3004\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/media\/3005"}],"wp:attachment":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=3004"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=3004"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=3004"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}