Orkes Conductor Evaluator Remote Code Execution
What is the Vulnerability? Attackers are actively targeting Orkes Conductor servers vulnerable to CVE-2026-58138, a critical unauthenticated remote code execution vulnerability in its GraalVM script evaluators. FortiGuard telemetry is observing active attack attempts targeting vulnerable Orkes Conductor deployments. In the last 24 hours, FortiGuard IPS blocked 1,290 attack attempts, representing a 132% increase in daily…
|
What is the Vulnerability? |
Attackers are actively targeting Orkes Conductor servers vulnerable to CVE-2026-58138, a critical unauthenticated remote code execution vulnerability in its GraalVM script evaluators. FortiGuard telemetry is observing active attack attempts targeting vulnerable Orkes Conductor deployments. In the last 24 hours, FortiGuard IPS blocked 1,290 attack attempts, representing a 132% increase in daily activity. Over the last seven days, 6,696 attempts were blocked, with activity increasing 17% week over week. The highest volumes of observed attack activity originated from Germany, Hong Kong, Indonesia, the United Arab Emirates, and India. The vulnerability allows an unauthenticated attacker to submit a malicious workflow definition containing JavaScript or Python expressions to the Conductor workflow API. Because vulnerable evaluators can be configured with unrestricted host access, the attacker can escape the intended scripting environment and execute arbitrary operating system commands with the privileges of the Conductor process. Public proof-of-concept exploit code is available, including a working exploit targeting Conductor v3.23.0. Exploit material has also been published through Exploit-DB, increasing the likelihood of opportunistic scanning and exploitation of exposed deployments. |
|
What is the recommended Mitigation? |
Organizations using affected versions should upgrade to Conductor 3.30.2 or later, which addresses the vulnerability. Until systems can be upgraded: Because the vulnerability is unauthenticated and remotely exploitable, Internet-exposed instances should be treated as a high priority for remediation. |
|
What FortiGuard Coverage is available? |
• FortiGuard IPS Service: Detects and blocks network-based exploitation attempts targeting the Orkes Conductor vulnerability, including malicious requests attempting to trigger remote code execution. |
