PT-2026-53941 · Orkes · Orkes Conductor

·

CVE-2026-58138

·

Published

2026-06-30

·

Updated

2026-07-16

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Orkes Conductor versions 3.21.21 through 3.30.1
Description An unauthenticated remote code execution issue allows remote attackers to execute arbitrary OS commands by submitting inline workflow definitions containing malicious JavaScript or Python expressions to the workflow API endpoint. This occurs when unsandboxed GraalVM evaluators are configured with HostAccess.ALL or allowAllAccess(true) through INLINE, LAMBDA, DO WHILE, and SWITCH task types, enabling the invocation of system commands via Java reflection or direct subprocess calls.
Recommendations Update to version 3.30.2 or later.

Exploit

Fix

RCE

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-58138

Affected Products

Orkes Conductor