CVE-2026-58138

Critical9.8Published on June 30, 2026

Orkes Conductor 3.21.21 before 3.30.2 contains an unauthenticated remote code execution vulnerability that allows remote attackers to execute arbitrary OS commands by submitting inline workflow definitions containing malicious JavaScript or Python expressions to the workflow API endpoint prior to authentication. Attackers can exploit unsandboxed GraalVM evaluators configured with HostAccess.ALL or allowAllAccess(true) through INLINE, LAMBDA, DO_WHILE, and SWITCH task types to invoke arbitrary system commands via Java reflection or direct subprocess calls.

Early warning: exploitation observed

  • Exploitation observed since Jul 27, 2026
  • Not yet in the official CISA catalogue
  • First attack observed 26 days after disclosure
  • Confirmed by sensors, not only by reports

Source: VulnCheck KEV · Sep 16, 2026 Sep 15, 2026 Sep 10, 2026 Sep 9, 2026 Sep 5, 2026 Sep 4, 2026

CVSS score9.8 / 10CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness type (CWE)CWE-94

Related articles

This product uses the NVD API but is not endorsed or certified by the NVD.

CVE database