Attackers Are Hammering Orkes Conductor Servers With No-Login Attacks That Run OS Commands
CVE-2026-58138 (CVSS 9.8) is unauthenticated remote code execution in Orkes Conductor via crafted inline workflows. Fortinet blocked about 1,290 attempts in 24 hours around 8 and 9 September and nearly 7,000 from 2 to 9 September. Patch to 3.30.2 or later.

SecurityWeek (Ionut Arghire, 18 September 2026) reported active exploitation of a critical unauthenticated remote code execution bug in Orkes Conductor. The Hacker News (Ravie Lakshmanan, 19 September 2026) carried Fortinet's outbreak alert on the same flaw.
This is active exploitation reporting of CVE-2026-58138, scored CVSS 9.8, backed by a Fortinet outbreak alert and Empirical Security technical notes. It is not a CISA Known Exploited Vulnerabilities listing, and it is not a report that Orkes Cloud was breached.
Orkes Conductor is an open-source framework for orchestrating microservices, workflows, and AI agents. Attackers submit crafted inline workflow definitions to the workflow API. They embed malicious JavaScript or Python in INLINE, LAMBDA, DO_WHILE, and SWITCH tasks.
The root cause is a GraalVM evaluator configured with HostAccess.ALL or allowAllAccess(true). That setting disables the sandbox, so attacker code can reflect into the Java runtime or spawn OS commands as the Conductor process. The Conductor process often runs with root privileges, though that is not true of every deployment.
The open-source server enforces no authentication by default and leaves the workflow API open. Empirical Security told SecurityWeek a single unauthenticated POST can register and start a hostile workflow.
The flaw affects 3.21.21 before 3.30.2 and was patched in Conductor 3.30.2 in June 2026. Proof of concept code appeared in early August. Empirical saw in-the-wild exploitation on 21 August.
Fortinet blocked about 1,290 attack attempts in a 24-hour window around 8 and 9 September, and nearly 7,000 between 2 and 9 September, about 132 percent higher daily activity. Attack traffic was noted from Germany, Hong Kong, Indonesia, the UAE, and India.
If a box is still unpatched, restrict external access to Conductor workflow API endpoints, put instances behind network ACLs or firewalls, and watch for suspicious workflow submissions and unexpected command execution.
Related exploit tape includes Kestra's auth-bypass RCE, JFrog Artifactory auth bypass, and Cisco ISE login bypass.
Upgrade every internet-reachable Conductor instance to 3.30.2 or later tonight, then hunt for unexpected INLINE or LAMBDA workflows and unexpected process launches from the Conductor user.
Cyberpresso: daily cyber & AI brief
Free daily newsletter, read in 5 minutes.
Subscribe free