The Patch Shipped in June. The Exploit Wave Came in September — Pre-Auth RCE in Orkes Conductor

CVE-2026-58138 is an unauthenticated remote code execution flaw in Orkes Conductor, the workflow orchestration platform that increasingly sits underneath agentic systems, disclosed by VulnCheck on 30 June 2026 and fixed in Conductor 3.30.2. It scores 9.8 Critical on CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H (9.3 on CVSS 4.0), is classed as CWE-94 code injection, and affects versions 3.21.21 through 3.30.1. The fix had been available for over two months when Fortinet telemetry showed attackers hammering it at scale: 1,290 blocked attempts in a single 24-hour period as of 9 September, and roughly 6,700 between 2 and 9 September.

This is a patch-gap story more than a novelty story. Everything defenders needed — advisory, fixed release, two patch commits — existed in June. The exploitation arrived in September anyway.

A workflow definition is a program, and it arrived before login

The vulnerable path is the workflow API endpoint, which accepts inline workflow definitions prior to authentication. A definition can embed JavaScript or Python expressions in INLINE, LAMBDA, DO_WHILE, and SWITCH task types, and those expressions are evaluated by GraalVM script evaluators configured with HostAccess.ALL or allowAllAccess(true) — effectively no sandbox at all. From there, arbitrary OS commands follow through Java reflection or direct subprocess calls. No credentials, no user interaction, network-reachable.

Note what the evaluators are: a documented feature, not a backdoor. Somebody decided the orchestration engine should be able to run host-level code from workflow text, configured the evaluator for maximum capability, and put that evaluator behind an endpoint that answers before it checks who is asking. Each decision is defensible in a demo; together they are unauthenticated RCE. This is the same composition pattern as the DebugMCP drive-by chain, where individually unremarkable choices — a local server, a stateless transport, a Windows path convention — composed into code execution.

Why an orchestration engine is the wrong place for this bug

Conductor is not a peripheral tool. It is the execution plane: it holds credentials for downstream systems, schedules work across services, and in agentic deployments increasingly executes the plans agents produce. Compromise of the orchestrator inherits every integration the orchestrator was trusted with — the standing-authority problem this site keeps documenting, from an identity-governance server running as LocalSystem to an agent harness holding plaintext credentials. The workflow API is also exactly the kind of endpoint that ends up internet-exposed for partner integrations and managed-service convenience, which is why pre-auth matters more here than in a purely internal scheduler.

The timeline defenders should internalize

VulnCheck published the advisory on 30 June with credit to researcher seqradev, NVD ingested the CVE the same day, and the fix shipped as 3.30.2 with two patch commits. VulnCheck carries the advisory in its KEV database. Then nothing visible happened for two months — and then, in the first week of September, thousands of exploit attempts per week with a triple-digit single-day spike. That lag is the normal shape of modern exploitation: disclosure, exploit maturation, scanning, then a campaign. A June patch that is still unapplied in September is not a theoretical exposure; the telemetry says it is an actively probed one. If your Conductor upgrade is queued behind feature work, this is the CVE to pull it in front of.

What to do

  • Upgrade to Conductor 3.30.2 or later. Versions 3.21.21 through 3.30.1 are affected; the fixed release has been available since June.
  • Get the workflow API off the internet. An endpoint that executes workflow text has no business answering unauthenticated traffic from arbitrary networks, patched or not.
  • Audit every GraalVM evaluator for HostAccess.ALL / allowAllAccess(true). Evaluators that run workflow-supplied expressions should be sandboxed to the minimum host access the tasks require — this is the configuration the exploit depends on.
  • Hunt for anomalous workflow definitions. Look for recently created or modified definitions containing inline script expressions, reflection calls, or subprocess invocations, especially ones submitted outside normal deployment pipelines.
  • Treat orchestrators as tier-zero. Anything that holds downstream credentials and executes agent-produced plans deserves the network isolation and monitoring you give identity infrastructure.

Sources: