Critical Pre-Auth RCE in Orkes Conductor Workflow Platform Exploited in the Wild
- ID
- 26268
- Status
- summarized
- Published
- 19 Sep 2026, 4:18 PM
- Fetched
- 19 Sep 2026, 5:25 PM
- Provider
- The Hacker News
- Category
- security
- Original URL
- https://thehackernews.com/2026/09/critical-pre-auth-rce-in-orkes.html
- Source URL
- https://feeds.feedburner.com/TheHackersNews
Summary
- Score
- 8.5
- Created
- 19 Sep 2026, 5:25 PM
- Tags
- Audience
- developersai_agent_userssaas_founders
What happened
A critical pre-auth remote code execution vulnerability (CVE-2026-58138, CVSS 9.8) in Orkes Conductor is being actively exploited in the wild. Attackers are bypassing authentication to execute arbitrary OS commands by submitting malicious JavaScript or Python expressions via the workflow API on versions 3.21.21 to 3.30.1. Fortinet reported blocking nearly 7,000 attack attempts between September 2 and 9, 2026.
Why it matters
If you are running Orkes Conductor for workflow or AI agent orchestration, you must patch to version 3.30.2 or block external access to the workflow API immediately, as attackers are actively taking over unpatched servers using this flaw.
Discussion angle
How to secure workflow orchestration engines that allow inline code execution (like GraalVM evaluators) and the risks of exposing workflow APIs externally.