CVE-2026-58138

Confirmed PUBLISHED

Orkes Conductor 3.21.21 < 3.30.2 Unauthenticated RCE via GraalVM Script Evaluators

Vendor: conductor-oss Product: conductor

Not yet in CISA KEV

Exploited in the wild Active exploitation observed PoC available

Recommended Action

Prioritize immediate patching and validate internet-facing exposure. Monitor for matching exploitation attempts in your environment.

Confidence
Confirmed
Exploitation Status
Active exploitation observed
Observed in Sensors
Yes
Attempts (30d)
1
Unique Attacker IPs
1
CISA KEV
Not yet in CISA KEV
CVSS / EPSS
9.3 Critical EPSS 1.2%

At a Glance

Orkes Conductor 3.21.21 before 3.30.2 contains an unauthenticated remote code execution vulnerability that allows remote attackers to execute arbitrary OS commands by submitting inline workflow definitions containing malicious JavaScript or Python expressions to the workflow API endpoint prior to authentication. Attackers can exploit unsandboxed GraalVM evaluators configured with HostAccess.ALL or allowAllAccess(true) through INLINE, LAMBDA, DO_WHILE, and SWITCH task types to invoke arbitrary system commands via Java reflection or direct subprocess calls.

python
CVE Published
Jun 30, 2026
Exploitation Reported
Jul 25, 2026
CVSS
9.3 Critical
EPSS
1.2%
Remote Low complexity No user interaction Unauthenticated

Sensor telemetry available

Affected Versions

Vendor Product Version Status
conductor-oss
conductor

3.21.21 to < 3.30.2

Affected

CVE References

  • Patch Commit (1) github.com · Patch https://github.com/conductor-oss/conductor/commit/87a7d96aabbb706d6e8...
  • Patch Commit (2) github.com · Patch https://github.com/conductor-oss/conductor/commit/c691e35e768caeb802c...
  • Third-Party Advisory — vulncheck.com vulncheck.com · Third-Party Advisory https://www.vulncheck.com/advisories/orkes-conductor-unauthenticated-...
  • Release Notes github.com · Release Notes https://github.com/conductor-oss/conductor/releases/tag/v3.30.2
  • Related CVE cve.org · CVE Record https://www.cve.org/CVERecord?id=CVE-2025-26074