DEV Community

Mark0
Mark0

Posted on

Critical Pre-Auth RCE in Orkes Conductor Workflow Platform Exploited in the Wild

⚠️ Region Alert: UAE/Middle East

Fortinet has issued an outbreak alert regarding the active exploitation of CVE-2026-58138, a critical unauthenticated remote code execution (RCE) vulnerability in Orkes Conductor. The flaw, which carries a CVSS score of 9.8, allows attackers to execute arbitrary OS commands by submitting malicious workflow definitions through the API before authentication. This occurs due to unsandboxed GraalVM evaluators allowing access to the host system via Java reflection or subprocess calls.

Cybersecurity telemetry has recorded a significant surge in exploitation attempts, with thousands of attacks originating from various regions including the U.A.E., Germany, and Indonesia. Organizations are strongly urged to update to Orkes Conductor version 3.30.2 or later. If patching is delayed, access to the workflow API should be strictly restricted and monitored for suspicious activity.


Read Full Article

Top comments (0)