{
  "id": 8348469,
  "title": "Orkes Conductor CVE-2026-58138: Exploitation Activity Observed Against Unauthenticated Workflow RCE",
  "url": "https://urgent.news/2026/09/19/orkes-conductor-cve-2026-58138-exploitation-activity-observed-against",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-09-19T00:53:32.000Z",
  "source": {
    "name": "Dev.to",
    "slug": "dev-to",
    "url": "https://dev.to/anoymask/orkes-conductor-cve-2026-58138-exploitation-activity-observed-against-unauthenticated-workflow-rce-2gkk"
  },
  "original_language": "en",
  "account": "The CVE-2026-58138 vulnerability impacts the Orkes Conductor OSS Workflow API, which lacks authentication by default. This allows attackers to send malicious workflow definitions containing JavaScript or Python expressions through an unauthenticated API. As a result, OS commands can be executed with the privileges of the Conductor process, often root, potentially granting access to connected systems and sensitive data. Empirical Security observed exploitation activity in September 2026, while SecurityWeek reported that Fortinet blocked approximately 1,300 attempts. Although successful code execution in these attempts has not been publicly confirmed, the vulnerability poses a critical risk if exploited.",
  "summary": "1. Basic Information Original Title: September 2026 CVE of the Month: The 9.8 Nobody Knows They Are Running (CVE-2026-58138) Source: Empirical Security Publication Date: September 1, 2026 Updated Date: None Severity: Critical Basis of Severity: Sending malicious workflow definitions to the Conductor OSS Workflow API, which lacks authentication by default, allows OS commands to execute with the…",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}