AI Weekly Malaysia

Back to items Summaries

Critical Pre-Auth RCE in Orkes Conductor Workflow Platform Exploited in the Wild

ID
26268
Status
summarized
Published
19 Sep 2026, 4:18 PM
Fetched
19 Sep 2026, 5:25 PM
Provider
The Hacker News
Category
security
Original URL
https://thehackernews.com/2026/09/critical-pre-auth-rce-in-orkes.html
Source URL
https://feeds.feedburner.com/TheHackersNews

Summary

Score
8.5
Created
19 Sep 2026, 5:25 PM
Tags
Audience
developersai_agent_userssaas_founders

What happened

A critical pre-auth remote code execution vulnerability (CVE-2026-58138, CVSS 9.8) in Orkes Conductor is being actively exploited in the wild. Attackers are bypassing authentication to execute arbitrary OS commands by submitting malicious JavaScript or Python expressions via the workflow API on versions 3.21.21 to 3.30.1. Fortinet reported blocking nearly 7,000 attack attempts between September 2 and 9, 2026.

Why it matters

If you are running Orkes Conductor for workflow or AI agent orchestration, you must patch to version 3.30.2 or block external access to the workflow API immediately, as attackers are actively taking over unpatched servers using this flaw.

Discussion angle

How to secure workflow orchestration engines that allow inline code execution (like GraalVM evaluators) and the risks of exposing workflow APIs externally.

Top