Vulnerability
Published 2026-09-09
Verified 2026-09-19

Orkes/OSS Conductor unauth RCE CVE-2026-58138 (CVSS 9.8); exploited; fix 3.30.2

FortiGuard Threat Signal / Outbreak Alert (released 9 September 2026; SecurityWeek coverage 18 September) tracks active exploitation of CVE-2026-58138 in Orkes Conductor / conductor-oss: unauthenticated remote code execution via GraalVM script evaluators. Attackers POST a workflow definition with hostile INLINE (also LAMBDA, DO_WHILE, SWITCH) JavaScript or Python expressions to the workflow API; evaluators configured with HostAccess.ALL / unrestricted host access escape the sandbox and run OS commands as the Conductor process (often root). Open-source Conductor leaves the workflow API unauthenticated by default. NVD/VulnCheck describe affected range Conductor 3.21.21 before 3.30.2; complete fix in 3.30.2 (partial denyAccess blocklist on 3.30.0/3.30.1 is incomplete). Public PoC exists (incl. Exploit-DB / lab repos targeting ~3.23.0). FortiGuard telemetry: ~1,290 IPS blocks in 24h (rising) and ~6,696 over seven days; top observed sources Germany, Hong Kong, Indonesia, UAE, India. Empirical Security cited in-the-wild from ~21 August after August PoC. CVSS 9.8 reported (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). Not claiming Australia KEV. Primary: FortiGuard threat signal; secondary: SecurityWeek 18 Sep / NVD.

Product
Orkes Conductor / conductor-oss workflow orchestration (GraalVM INLINE/LAMBDA evaluators)
Versions
Conductor 3.21.21 through before 3.30.2 (complete fix 3.30.2+); 3.30.0/3.30.1 partial blocklist incomplete
CVSS
(CVSS 3.1 Critical; SecurityWeek / public advisory materials)
Exploited in Australia?
unknown
Patch to
Upgrade to Conductor 3.30.2 or later; do not expose workflow API to the internet; firewall/segment Conductor; monitor suspicious workflow submissions and unexpected child processes from Conductor

Primary: FortiGuard — Orkes Conductor evaluator RCE Threat Signal (CVE-2026-58138) · Vendor: conductor-oss/conductor (upgrade to 3.30.2+) · CVE: CVE-2026-58138 · SecurityWeek — Orkes Conductor CVE-2026-58138 exploited (18 Sep 2026); also NVD

vulnerabilities cloud ai