Skip to content
TodayPrism
Updated 2h agoTech & Cyber

Critical Pre-Auth RCE in Orkes Conductor Workflow Platform Exploited

Headline by Prism · from 1 report

A critical pre-authentication remote code execution vulnerability in the Orkes Conductor workflow platform is being actively exploited in the wild.

1 outlet · 1 report · EnglishOne source so far

The record

Written from the 1 report below. Nothing here is unsourced.

  • Orkes Conductor versions 3.21.21 through 3.30.1 are vulnerable to a remote code execution flaw that allows attackers to run arbitrary OS commands by submitting malicious workflow definitions.
  • The vulnerability stems from insecure configurations in GraalVM evaluators, which can be manipulated to bypass intended scripting limitations.
  • Cybersecurity firms report an increase in active exploitation attempts globally since early September 2026.

What to watch next

  • Ongoing monitoring for suspicious workflow submissions and unauthorized command execution on Conductor instances.
  • Continued analysis of exploit attempts originating from various global regions.

Who said what1

Only words found exactly in the article are shown, attributed and linked to the line they came from.

Fortinet

1 quote · 1 outlet

  • Because vulnerable evaluators can be configured with unrestricted host access, the attacker can escape the intended scripting environment and execute arbitrary operating system commands with the privileges of the Conductor process
    [1]The Hacker News2h agoOpen at the quote ↗
    In the article

    it has observed attackers actively targeting Orkes Conductor servers susceptible to CVE-2026-58138 by submitting crafted workflow definitions containing JavaScript or Python expressions to the Conductor workflow API. " Because vulnerable evaluators can be configured with unrestricted host access, the attacker can escape the intended scripting environment and execute arbitrary operating system commands with the privileges of the Conductor process ," Fortinet said. As of September 9, 2026, the company said it had blocked 1,290 attack attempts within a span of 24 hours, representing a 132% increase in daily activity. Nearly 7,000 attempts were blocked between

Coverage1

1 report
English national1

All filed from India

Named Germany · Hong Kong SAR China · Indonesia · United Arab Emirates · India · France · United States · Orkes Conductor · Empirical Security · Fortinet · National Vulnerability Database · Previdian

Ask this story

Answers cite the reports above, or say they can't.

← Today’s record

Critical Pre-Auth RCE in Orkes Conductor Workflow Platform Exploited | Prism