Orkes Conductor has an unauthenticated remote code execution vulnerability, tracked as CVE-2026-58138, and it is already being exploited. The Orkes Conductor vulnerability lets an attacker submit an inline workflow definition and get code running on the server without logging in first, which is about as severe as a pre-auth bug gets. It carries a CVSS v3.1 score of 9.8 and a CVSS v4 score of 9.3, and affects Orkes Conductor from version 3.21.21 up to, but not including, 3.30.2. The Hacker News, citing Fortinet, reports that the flaw is being actively exploited in the wild.
What the Orkes Conductor vulnerability lets an attacker do
The bug sits in how Conductor processes inline workflow definitions submitted to the platform. Conductor is a workflow orchestration engine used to coordinate microservice tasks, so a compromised instance typically has broad network reach into whatever it’s coordinating. An unauthenticated attacker who can reach the API doesn’t need a valid session or credentials, just a crafted workflow submission, to get the server to execute their code. A 9.8 out of 10 on CVSS v3.1 is about as close to a full house as the scoring rubric gets: network-reachable, no privileges required, no user interaction needed. That makes this a full remote takeover rather than a data-exposure bug: whoever controls the workflow engine controls every task it’s allowed to trigger downstream.
The fix is a version upgrade, not a configuration workaround. Operators running an affected build should:
- Check the running version against the 3.21.21 to 3.30.2 range
- Upgrade to 3.30.2 or later
- Review logs for workflow submissions that don’t match known automation, since exploitation is already under way
Why Orkes Conductor isn’t on CISA’s exploited list yet
CISA’s Known Exploited Vulnerabilities Catalog update on 18 September 2026 wasn’t about Orkes Conductor. It added CVE-2025-39682, a Linux kernel flaw, citing evidence of active exploitation as required under Binding Operational Directive 26-04, which sets remediation deadlines for federal agencies once a vulnerability that grants total control of an asset lands on the catalogue. BOD 26-04 also requires agencies to check whether a system was already compromised before a patch was applied, a reasonable caution for any flaw that’s being exploited ahead of widespread patching. The directive itself only binds federal civilian agencies, but CISA has said it wants all organisations to prioritise remediation using the same catalogue.
Orkes Conductor’s pre-auth RCE fits the profile the directive targets, but as of that advisory CVE-2026-58138 hadn’t been added, despite the exploitation Fortinet reported.
We’ve tracked this gap before. In August, CISA ordered federal agencies to patch an actively exploited flaw in Ray within three days of its KEV listing. That case showed how fast the clock starts once a vulnerability is catalogued. Orkes Conductor’s flaw hasn’t reached that point, so for now the deadline is whatever an operator sets after reading the vendor advisory, not a federal one.
Watch for whether CVE-2026-58138 lands on the KEV catalogue next; if it does, expect a fixed deadline in the same short-window style as the Ray case. Until then, anyone running Orkes Conductor should treat the 3.30.2 release itself as the deadline, since active exploitation doesn’t wait for a catalogue listing before it starts counting against you.








