Executive Summary
CVE-2026-58138 is a critical unauthenticated remote code execution flaw in Orkes / open-source Conductor (conductor-oss/conductor). Vulnerable versions evaluate JavaScript and Python expressions in workflow task types inside GraalVM polyglot contexts configured with unrestricted host access. Combined with a workflow API that requires no authentication by default on OSS deployments, a remote unauthenticated party who can reach the API can cause arbitrary OS command execution with the privileges of the Conductor process.
CVSS 3.1 is 9.8 Critical (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H); CVSS 4.0 is 9.3 Critical (VulnCheck / NVD). CWE-94 (Improper Control of Generation of Code / Code Injection). CNA: VulnCheck.
Fixed in Conductor v3.30.2 (released June 3, 2026; changelog “Restrict graaljs further”). CVE formally published June 30, 2026—about four weeks after the patch. Affected range: 3.21.21 before 3.30.2.
Not on CISA KEV: As of September 29, 2026 (CISA KEV catalog version 2026.09.27), CVE-2026-58138 is absent from the CISA Known Exploited Vulnerabilities catalog. Do not treat this as a CISA KEV listing. VulnCheck KEV is a separate catalog (secondary reports add date ~July 27, 2026).
Active exploitation signals nonetheless exist: FortiGuard Outbreak Alert (released September 15, 2026) reports active attack attempts, with telemetry of roughly 6,696–7,000 blocked attempts September 2–9, 2026 and a spike around September 9. CSA AI Safety Initiative research note (September 20, 2026) assesses critical unauthenticated remote code execution and recommends emergency patching. No dedicated Orkes CVE PSIRT blog or GitHub Security Advisory was located as of September 29, 2026.
Technical Information
Vulnerable Conductor versions evaluate JavaScript/Python expressions in workflow task types INLINE, LAMBDA, DO_WHILE, and SWITCH inside GraalVM polyglot contexts configured with unrestricted host access (HostAccess.ALL / allowAllAccess(true)). Combined with a workflow API that requires no authentication by default on OSS deployments, a remote unauthenticated party who can reach the API can cause arbitrary OS command execution with the privileges of the Conductor process (NVD description; CSA 2026-09-20; FortiGuard).
Internet-reachable workflow API on unpatched hosts is the critical exposure. OSS server enforces no authentication by default and leaves the workflow API open (quoted via SecurityWeek / Empirical / CSA). Impact emphasis is on self-hosted / internet-facing OSS Conductor; Orkes cloud-managed products may have different auth defaults—not confirmed in a primary vendor CVE PSIRT.
Fix shipped as OSS release v3.30.2 (2026-06-03) with release-note language “Restrict graaljs further” (PR #1123) rather than a CVE-titled security advisory. NVD also cites two patch commits. No GHSA was found on the conductor-oss/conductor security advisories listing as of 2026-09-29.
Primary sources reviewed (NVD, VulnCheck, FortiGuard, CSA, THN, SecurityWeek) do not explicitly map observed TTPs to MITRE ATT&CK technique IDs. This advisory does not invent ATT&CK mappings or actor attribution. FortiGuard geographic origin volumes of attack traffic are attack-infrastructure geography, not confirmed attribution.
Affected Product Versions
Product: Orkes Conductor / open-source Conductor (conductor-oss/conductor on GitHub). Originally developed at Netflix; OSS project now maintained / commercially supported by Orkes (per CSA).
| Item | Detail |
|---|---|
| Affected versions | 3.21.21 ≤ version < 3.30.2 (semver; “3.21.21 before 3.30.2”) per NVD / VulnCheck / CSA |
| Fixed | 3.30.2 or later |
| Exposure model | OSS default: no authentication on workflow API; internet-reachable unpatched hosts are critical |
Conductor is an orchestration and workflow platform often deployed in cloud supplier stacks and self-hosted in customer and MSP environments. It is increasingly used in agentic AI pipelines (LLM calls, tool access, human-in-the-loop) per CSA.
Netflix-era forks or third-party redistributions outside the NVD package scope are not confirmed in this research.
Workaround and Mitigation
- Upgrade all Conductor instances to 3.30.2 or later immediately (GitHub release; FortiGuard; NVD).
- Inventory all Conductor deployments—including informal, experimental, and agentic-AI instances (containers, VMs, Kubernetes services exposing workflow APIs).
- Until patched: restrict external access to workflow API endpoints (firewall allowlist, VPN, reverse proxy requiring authentication); do not expose vulnerable Conductor services directly to the Internet; place instances behind network segmentation.
- Detection / response hygiene (FortiGuard / CSA — not exploit recipes): monitor for suspicious workflow submissions and unexpected command execution from the Conductor process; audit logs for unexpected workflow definitions using INLINE, LAMBDA, DO_WHILE, or SWITCH with embedded script expressions.
- If internet exposure during the vulnerable window cannot be ruled out: treat as high priority; rotate credentials, API keys, and secrets accessible to the Conductor process (LLM keys, DB credentials, service tokens); review for post-exploitation evidence—do not assume patch alone clears prior compromise.
- Run Conductor under a non-privileged account; disable unrestricted GraalVM host access where workflow logic does not require it (CSA short-term / strategic).
Treat internet-facing pre-patch Conductor as compromised-until-proven-clean.
Indicators of Compromise
No authoritative public list of malware hashes, C2 domains, or definitive attacker IP/CIDR blocklists was located in FortiGuard Outbreak Alert, CSA note, NVD, VulnCheck advisory, or THN/SecurityWeek summaries as of 2026-09-29. Honest empty for classic IoCs.
Behavioral / hunting notes only (sourced guidance):
- Suspicious workflow submissions and unexpected command execution originating from the Conductor process (FortiGuard).
- Unexpected workflow definitions using INLINE, LAMBDA, DO_WHILE, or SWITCH with embedded script expressions (CSA).
- FortiGuard reports geographic origin volumes of observed attack traffic (Germany, Hong Kong, Indonesia, UAE, India)—not treated as actionable IoCs without published IP/CIDR lists; not confirmed attribution.
- Previdian honeypot (via THN): two unique source IPs (France and US) without publishing addresses in retrieved text.
- FortiGuard numbers are blocked attempts, not confirmed enterprise breach counts.
Do not invent ATT&CK technique IDs or additional IoCs beyond what primary and clearly labeled secondary sources publish. Detection may also rely on vendor IPS signatures (FortiGuard IPS coverage claimed by Fortinet—product-specific).
References
- NVD: CVE-2026-58138 — https://nvd.nist.gov/vuln/detail/CVE-2026-58138
- NVD REST — https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2026-58138
- VulnCheck advisory — https://www.vulncheck.com/advisories/orkes-conductor-unauthenticated-rce-via-graalvm-script-evaluators
- GitHub release v3.30.2 — https://github.com/conductor-oss/conductor/releases/tag/v3.30.2
- Patch commits (NVD refs) — https://github.com/conductor-oss/conductor/commit/87a7d96aabbb706d6e84f812b93da5165028d18f ; https://github.com/conductor-oss/conductor/commit/c691e35e768caeb802c9f06ecdd9674c80081af1
- FortiGuard Outbreak Alert — https://fortiguard.fortinet.com/outbreak-alert/orkes-conductor-rce
- FortiGuard Threat Signal — https://www.fortiguard.com/threat-signal-report/6527/orkes-conductor-evaluator-remote-code-execution
- CSA Research Note, 2026-09-20 — https://labs.cloudsecurityalliance.org/research/csa-research-note-orkes-conductor-rce-exploitation-20260920/
- The Hacker News, 2026-09-19 — https://thehackernews.com/2026/09/critical-pre-auth-rce-in-orkes.html
- SecurityWeek, 2026-09-18 — https://www.securityweek.com/critical-orkes-conductor-vulnerability-exploited-in-attacks/
- Hexnode Threat Watch, 2026-09-22 — https://www.hexnode.com/threat-watch/orkes-conductor-cve-2026-58138/
- CISA KEV JSON (confirm absence; not a listing) — https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json
Third-Party Risk Bridge: Conductor as Cloud Orchestration Control Plane
Orkes Conductor / Conductor OSS is workflow orchestration used in microservices and increasingly in agentic AI pipelines—LLM calls, tool access, human-in-the-loop—so compromise of the orchestration host is a supplier and customer cloud control-plane risk, not merely an app bug. CVE-2026-58138 pairs unsandboxed GraalVM evaluators with default-no-auth workflow APIs for unauthenticated OS command execution; FortiGuard Outbreak Alert (2026-09-15) and CSA (2026-09-20) show active attack attempts even though the CVE is not on CISA KEV as of 2026-09-29. Ask every MSP or cloud integrator: Do you run self-hosted Conductor (or Orkes-managed)? Exact version (≥ 3.30.2)? Is the workflow API internet-facing, and what auth is enforced? If any internet-facing build ran in the 3.21.21–3.30.1 window, require compromised-until-proven-clean hunting plus rotation of secrets available to the Conductor process.
Book a demo to see how Rescana tracks cloud orchestration and agentic-pipeline vendors for version attestation, internet-exposure evidence, and post-exploitation close criteria.
Forward this advisory to your TPRM owner if a supplier or MSP operates Conductor for your estate—they own the ≥ 3.30.2 attestation, workflow-API exposure, and secret-rotation asks above.



