importantSYS.SOURCE: The Hacker News• 2026-09-19T13:48:54+05:30
Critical Pre-Auth RCE Vulnerability in Orkes Conductor Workflow Platform Exploited in the Wild
A critical pre-authenticated remote code execution (RCE) vulnerability (CVE-2026-58138) in Orkes Conductor allows attackers to execute arbitrary commands without authentication, with active exploitation reported. Organizations are advised to upgrade to version 3.30.2 or later to mitigate the risk.
A critical vulnerability impacting Orkes Conductor is being actively exploited in the wild, according to Fortinet.
The vulnerability in question is CVE-2026-58138 (CVSS v3.1 score: 9.8/CVSS v4 score: 9.3), which relates to a case of unauthenticated remote code execution.
"Orkes Conductor 3.21.21 before 3.30.2 contains an unauthenticated remote code execution vulnerability that allows remote
*** END OF TRANSMISSION ***