Back to advisories

Critical Orkes Conductor Vulnerability Exploited in Attacks

Orkes Conductor versions below 3.30.2 have an unauthenticated remote code execution vulnerability (CVE-2026-58138) that is actively being exploited. Attackers can execute arbitrary system commands by injecting malicious JavaScript or Python into workflow definitions. Any organization running Conductor in production is at immediate risk of full system compromise.

CRITICALAdvisorySep 20, 2026
Action required
Immediately patch Orkes Conductor to version 3.30.2 or later. In parallel, restrict external API access to Conductor instances and hunt for suspicious workflow definitions containing JavaScript or Python expressions in your environment.
Affected products
Orkes Conductor