Vendor
An unauthenticated remote code execution vulnerability (CVE-2026-58138) in Orkes Conductor allows attackers to execute arbitrary OS commands by submitting malicious JavaScript or Python expressions within inline workflow definitions to the workflow API endpoint before authentication, leveraging unsandboxed GraalVM evaluators through specific task types to invoke system commands via Java reflection or direct subprocess calls.