Critical Pre-Auth RCE in Orkes Conductor Workflow Platform Exploited in the Wild
AI-summarised brief · reviewed before publication
Orkes Conductor, a workflow automation platform, is under active exploitation due to CVE‑2026‑58138, a critical unauthenticated remote code execution flaw (CVSS 9.8). The vulnerability allows attackers to run arbitrary OS commands by submitting malicious JavaScript or Python expressions to the workflow API before authentication. Fortinet reported 1,290 attack attempts blocked in 24 hours, a 132% rise, with nearly 7,000 attempts since September 2, 2026. Primary sources of activity include Germany, Hong Kong, Indonesia, the U.A.E., and India. Affected users must upgrade to version 3.30.2 or later, or restrict API access and monitor for suspicious submissions.
💡 Why It Matters
- · The flaw exposes enterprise systems to uncontrolled command execution, enabling attackers to hijack critical infrastructure.
- · Rapid patching and strict API controls are essential to prevent widespread compromise.