Orkes Conductor CVE-2026-58138: Exploitation Activity Observed Against Unauthenticated Workflow RCE
1. Basic Information Original Title: September 2026 CVE of the Month: The 9.8 Nobody Knows They Are Running (CVE-2026-58138) Source: Empirical Security Publication Date: September 1, 2026 Updated Date: None Severity: Critical Basis of Severity: Sending malicious workflow definitions to the Conductor OSS Workflow API, which lacks authentication by default, allows OS commands to execute with the…
The CVE-2026-58138 vulnerability impacts the Orkes Conductor OSS Workflow API, which lacks authentication by default. This allows attackers to send malicious workflow definitions containing JavaScript or Python expressions through an unauthenticated API. As a result, OS commands can be executed with the privileges of the Conductor process, often root, potentially granting access to connected systems and sensitive data.
Empirical Security observed exploitation activity in September 2026, while SecurityWeek reported that Fortinet blocked approximately 1,300 attempts. Although successful code execution in these attempts has not been publicly confirmed, the vulnerability poses a critical risk if exploited.
Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.