CVE-2026-58138
Orkes Conductor 3.21.21 < 3.30.2 Unauthenticated RCE via GraalVM Script Evaluators
Description
Orkes Conductor 3.21.21 before 3.30.2 contains an unauthenticated remote code execution vulnerability that allows remote attackers to execute arbitrary OS commands by submitting inline workflow definitions containing malicious JavaScript or Python expressions to the workflow API endpoint prior to authentication. Attackers can exploit unsandboxed GraalVM evaluators configured with HostAccess.ALL or allowAllAccess(true) through INLINE, LAMBDA, DO_WHILE, and SWITCH task types to invoke arbitrary system commands via Java reflection or direct subprocess calls.
In plain language
AI Act nowOrkes Conductor versions 3.21.21 through before 3.30.2 can let an outsider take over the server, so small businesses using it should act now.
Unauthenticated RCE in Orkes Conductor through unsandboxed GraalVM JavaScript or Python evaluators embedded in workflow definitions submitted to the workflow API.
What to do now
- Check whether you run Conductor and identify its installed version.
- Upgrade Conductor to version 3.30.2.
- Until upgraded, restrict access to the workflow API to trusted internal systems.
- Review recent workflow submissions for unfamiliar scripts or commands.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:NUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Attack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
2 techniquesReferences
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-58138 and every CVE in our database. Create a free account — no credit card required.
Create Free Account