Critical Orkes Conductor Vulnerability Exploited in Attacks
Attackers actively exploit CVE-2026-58138 (CVSS 9.8), an unauthenticated RCE in Orkes Conductor via malicious JavaScript or Python expressions in inline workflows.
CVE-2026-58138 lets unauthenticated attackers submit workflow definitions containing hostile INLINE, LAMBDA, DO_WHILE, or SWITCH tasks; the GraalVM evaluator runs with HostAccess.ALL, disabling the sandbox so attacker code reflects into Java and executes OS commands, often as root. The flaw was patched in Conductor 3.30.2 in June, PoC code appeared in early August, and Empirical Security identified in-the-wild attacks on August 21. Fortinet blocked roughly 1,300 exploitation attempts between September 8 and 9 and issued an outbreak alert on the ongoing exploitation.