Critical Pre-Auth RCE in Orkes Conductor Workflow Platform Exploited in the Wild
High · The Hacker News ·
Exploited
What happened
Unauthenticated RCE (CVE-2026-58138, CVSS 9.8) in Orkes Conductor before 3.30.2 is actively exploited; any org running the workflow platform is at risk.
What to do now
Patch Orkes Conductor to 3.30.2 or later immediately. If patching is delayed, block internet access to the service, restrict to trusted IPs, and hunt for signs of compromise. Verify with vendor advisory.
CVE references
- CVE-2026-58138
Original source
AI-assisted analysis, sources cited. Verify with the vendor advisory before acting.