ZeroHour
Vendor

Empirical Security

1 mentions in 7 days · 1 in 30 days · 1 total · first seen · last

Timeline

Critical Orkes Conductor Vulnerability Exploited in Attacks

Attackers actively exploit CVE-2026-58138 (CVSS 9.8), an unauthenticated RCE in Orkes Conductor via malicious JavaScript or Python expressions in inline workflows.

CVE-2026-58138 lets unauthenticated attackers submit workflow definitions containing hostile INLINE, LAMBDA, DO_WHILE, or SWITCH tasks; the GraalVM evaluator runs with HostAccess.ALL, disabling the sandbox so attacker code reflects into Java and executes OS commands, often as root. The flaw was patched in Conductor 3.30.2 in June, PoC code appeared in early August, and Empirical Security identified in-the-wild attacks on August 21. Fortinet blocked roughly 1,300 exploitation attempts between September 8 and 9 and issued an outbreak alert on the ongoing exploitation.

SecurityWeekupdated · 19h agofirst · 1d agoExploit / PoC in the wild 2 sourcesCVE-2026-581382· 1 read

Related CVEs

  • Orkes Conductor 3.21.21 before 3.30.2 contains an unauthenticated remote code execution vulnerability that allows remote attackers to execute arbitrary OS comma
    Orkes Conductor 3.21.21 before 3.30.2 contains an unauthenticated remote code execution vulnerability that allows remote attackers to execute arbitrary OS commands by submitting inline workflow definitions containing malicious JavaScript or Python expressions to the workflow API endpoint prior to authentication. Attackers can exploit unsandboxed GraalVM evaluators configured with HostAccess.ALL or allowAllAccess(true) through INLINE, LAMBDA, DO_WHILE, and SWITCH task types to invoke arbitrary system commands via Java reflection or direct subprocess calls.

Appears with

Entities are extracted by the model from each article. Watching an entity keeps it in this browser only (no account); the watchlist page and dashboard alerts use it.