What is CVE-2026-58138?
Orkes Conductor 3.21.21 before 3.30.2 contains an unauthenticated remote code execution vulnerability that allows remote attackers to execute arbitrary OS commands by submitting inline workflow definitions containing malicious JavaScript or Python expressions to the workflow API endpoint prior to authentication. Attackers can exploit unsandboxed GraalVM evaluators configured with HostAccess.ALL or allowAllAccess(true) through INLINE, LAMBDA, DO_WHILE, and SWITCH task types to invoke arbitrary system commands via Java reflection or direct subprocess calls.
Timeline
- 2026-06-30Published to the U.S. National Vulnerability Database (NVD)
- 2026-07-14NVD record last updated
- 2026-09-20First covered in a defend.network daily briefing
Affected product
See advisory
Remediation Steps
- Upgrade Orkes Conductor to version 3.30.2 or later
- Apply authentication controls and network segmentation to isolate Conductor instances from untrusted networks
- Review access logs for evidence of exploitation or unauthorized access attempts
- Monitor for indicators of compromise linked to unauthenticated RCE abuse
References
Referenced in our briefings & reports
Browse all tracked CVEs in the defend.network CVE database →
🤖 This CVE page is generated by defend.network from NVD, CISA KEV, EPSS, and our verified daily briefings. Severity and exploitation data come from official sources; always verify remediation steps against the official vendor advisory before acting in production.