Exploited in the wild Orkes Conductor rce Orkes web-app
Critical Pre-Auth RCE in Orkes Conductor Workflow Platform Exploited in the Wild
CVE Tools coverage
Attackers are actively exploiting CVE-2026-58138, a pre-authentication remote code execution flaw in Orkes Conductor 3.21.21 before 3.30.2. Crafted workflow definitions can abuse unsandboxed JavaScript or Python evaluation to run operating-system commands as the Conductor process; organizations should upgrade to Conductor 3.30.2 or later and restrict access to workflow API endpoints.