S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Aug 30, 2026

CVE-2026-58138 Scanner

CVE-2026-58138 Scanner - Remote Code Execution (RCE) vulnerability in Orkes Conductor

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, subdomain, ipv4
CostFree
2.8k
Times Used
continuous scan runs
4.8k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2026-58138
9.3
CVSScritical
Exploitable remotely over the internet · no authentication required.

Orkes Conductor 3.21.21 before 3.30.2 contains an unauthenticated remote code execution vulnerability that allows remote attackers to execute arbitrary OS commands by submitting inline workflow definitions containing malicious JavaScript or Python expressions to the workflow API endpoint prior to authentication. Attackers can exploit unsandboxed GraalVM evaluators configured with HostAccess.ALL or allowAllAccess(true) through INLINE, LAMBDA, DO_WHILE, and SWITCH task types to invoke arbitrary system commands via Java reflection or direct subprocess calls.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
conductorby conductor-oss
AFFECTED< 3.30.2SAFE ✓≥ 3.30.2
Updated Aug 22, 2026View on NVD →
Detail

Orkes Conductor is widely used in enterprise environments for orchestrating microservice-based workflows. It facilitates business process automation and is known for its scalability and reliability. Organizations use Conductor to automate tasks, manage state in distributed systems, and handle complex workflows effortlessly. It's a tool specifically designed for developers and DevOps teams to streamline operations and improve efficiency. With its support for popular scripting languages and flexible architecture, Orkes Conductor integrates seamlessly with various platforms and services. This makes it a crucial component in modern, cloud-native application ecosystems.

Remote Code Execution (RCE) is a critical vulnerability that allows attackers to remotely execute arbitrary code on a vulnerable system. In Orkes Conductor, an RCE vulnerability can be exploited to execute system-level commands, potentially leading to a full system compromise. Unauthenticated attackers can leverage weaknesses in script evaluators to hijack system resources. This vulnerability is particularly severe as it doesn't require authentication, allowing external actors easy access to execute harmful operations. Addressing this vulnerability is crucial to protect against unauthorized access and potential data breaches.

The specific vulnerability in Orkes Conductor involves the INLINE workflow task that evaluates a user-supplied JavaScript expression within a GraalVM context. By exploiting the GraalVM script evaluators configured with HostAccess.ALL, attackers can access java.lang.Runtime and execute arbitrary commands. The attack surfaces include endpoints that manipulate workflow metadata and execute workflows with crafted JavaScript commands. Proper sanitization of input and restricted access to script evaluators are essential to mitigate this risk. Until the fix in 3.30.2, the system remains vulnerable to potentially devastating RCE attacks.

When exploited, this vulnerability allows an attacker to gain control of the Conductor server, execute arbitrary commands, and potentially access sensitive data. This can result in data breaches, service disruption, and unauthorized access to critical infrastructure. Exploitation could lead to the spread of malware, data exfiltration, or further attacks within the network. System integrity and confidentiality are compromised, posing significant risks to business continuity and reputation. Effective remediation strategies must be enacted promptly to prevent exploitation and secure vulnerable systems.

REFERENCES

Solution Advice
  • Upgrade to Orkes Conductor version 3.30.2 or later to mitigate the RCE vulnerability.
  • Regularly audit and monitor script evaluator configurations for unauthorized changes.
  • Implement strict input validation and sanitization for JavaScript executed in workflows.
  • Restrict access to critical endpoints like workflow metadata APIs to trusted networks only.
  • Continuously monitor network traffic for unusual patterns or signs of exploitation.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.