Orkes/OSS Conductor unauth RCE CVE-2026-58138 (CVSS 9.8); exploited; fix 3.30.2
FortiGuard Threat Signal / Outbreak Alert (released 9 September 2026; SecurityWeek coverage 18 September) tracks active exploitation of CVE-2026-58138 in Orkes Conductor / conductor-oss: unauthenticated remote code execution via GraalVM script evaluators. Attackers POST a workflow definition with hostile INLINE (also LAMBDA, DO_WHILE, SWITCH) JavaScript or Python expressions to the workflow API; evaluators configured with HostAccess.ALL / unrestricted host access escape the sandbox and run OS commands as the Conductor process (often root). Open-source Conductor leaves the workflow API unauthenticated by default. NVD/VulnCheck describe affected range Conductor 3.21.21 before 3.30.2; complete fix in 3.30.2 (partial denyAccess blocklist on 3.30.0/3.30.1 is incomplete). Public PoC exists (incl. Exploit-DB / lab repos targeting ~3.23.0). FortiGuard telemetry: ~1,290 IPS blocks in 24h (rising) and ~6,696 over seven days; top observed sources Germany, Hong Kong, Indonesia, UAE, India. Empirical Security cited in-the-wild from ~21 August after August PoC. CVSS 9.8 reported (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). Not claiming Australia KEV. Primary: FortiGuard threat signal; secondary: SecurityWeek 18 Sep / NVD.
- Product
- Orkes Conductor / conductor-oss workflow orchestration (GraalVM INLINE/LAMBDA evaluators)
- Versions
- Conductor 3.21.21 through before 3.30.2 (complete fix 3.30.2+); 3.30.0/3.30.1 partial blocklist incomplete
- CVSS
- (CVSS 3.1 Critical; SecurityWeek / public advisory materials)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - Exploited in Australia?
- unknown
- Patch to
- Upgrade to Conductor 3.30.2 or later; do not expose workflow API to the internet; firewall/segment Conductor; monitor suspicious workflow submissions and unexpected child processes from Conductor
Primary: FortiGuard — Orkes Conductor evaluator RCE Threat Signal (CVE-2026-58138) · Vendor: conductor-oss/conductor (upgrade to 3.30.2+) · CVE: CVE-2026-58138 · SecurityWeek — Orkes Conductor CVE-2026-58138 exploited (18 Sep 2026); also NVD
