CVE Tools
Back to feed
Exploited in the wild Orkes Conductor rce Orkes web-app

Critical Pre-Auth RCE in Orkes Conductor Workflow Platform Exploited in the Wild

The Hacker News·By The Hacker News··2 min read
CVE Tools coverage

Attackers are actively exploiting CVE-2026-58138, a pre-authentication remote code execution flaw in Orkes Conductor 3.21.21 before 3.30.2. Crafted workflow definitions can abuse unsandboxed JavaScript or Python evaluation to run operating-system commands as the Conductor process; organizations should upgrade to Conductor 3.30.2 or later and restrict access to workflow API endpoints.