VMTech
Discuss a project

Actively Exploited Orkes Conductor Flaw Enables Pre-Auth Code Execution

Actively Exploited Orkes Conductor Flaw Enables Pre-Auth Code Execution

Fortinet has warned that attackers are actively exploiting CVE-2026-58138, a critical unauthenticated remote code execution vulnerability in the Orkes Conductor workflow platform. The flaw affects Orkes Conductor versions 3.21.21 before 3.30.2 and carries a CVSS v3.1 score of 9.8 and a CVSS v4 score of 9.3.

On September 9, 2026, Fortinet blocked 1,290 attack attempts in 24 hours, a 132% increase in daily activity. Between September 2 and September 9, its controls blocked nearly 7,000 attempts directed at susceptible Conductor servers.

Workflow definitions can carry malicious expressions

The issue lies in the processing of inline workflow definitions submitted to the Conductor workflow API before authentication. An attacker can include malicious JavaScript or Python expressions and use the vulnerable evaluation path to execute arbitrary operating-system commands.

The NIST National Vulnerability Database says affected evaluators use GraalVM configurations with HostAccess.ALL or allowAllAccess(true). Those settings can let hostile code leave the intended scripting environment through Java reflection or direct subprocess calls.

The affected task types are INLINE, LAMBDA, DO_WHILE and SWITCH. In Fortinet's description, unrestricted host access enables an attacker to run commands with the privileges assigned to the Conductor process, making exposed workflow API endpoints a significant point of risk.

Attack activity spans multiple locations

Fortinet said most observed activity originated from Germany, Hong Kong, Indonesia, the United Arab Emirates and India. Separate telemetry from Previdian recorded three exploitation attempts against its honeypots from July 24, 2026, involving two unique IP addresses in France and the United States.

Empirical Security also reported detecting exploitation in the wild as recently as August 21, 2026. The reports indicate that exploitation was observed before Fortinet's September outbreak alert and that defenders should treat the flaw as an active exposure rather than a theoretical vulnerability.

Upgrade and reduce exposure

Orkes Conductor users should upgrade to version 3.30.2 or later, which addresses CVE-2026-58138. Where an immediate upgrade is not possible, Fortinet recommends restricting external access to Conductor workflow API endpoints and placing instances behind suitable network access controls.

Security and platform teams should also monitor for unusual workflow submissions and unexpected command execution. The practical business implication is clear: identify exposed Conductor deployments, apply the fixed release promptly, and use network restrictions and monitoring to reduce risk while remediation is underway.

#cybersecurity#vulnerability#appsecurity#orkesconductor
Open analytics
On the site 0 views
min read 3 19.09.2026
Instagram

Actively Exploited Orkes Conductor Flaw Enables Pre-Auth Code Execution

Open the post on Instagram ↗