criticalZero-Day

Orkes Conductor Unauthenticated Pre-Auth RCE (CVE-2026-58138) — Active Exploitation

First seen Sep 21, 2026 · Updated Sep 21, 2026 · CVSS 9.8

rcepre-authworkflow-engineconductoractive-exploitationagent-relevantorchestrationcve-2026-58138

A critical unauthenticated remote code execution vulnerability (CVE-2026-58138) in Orkes Conductor, a widely used workflow orchestration platform, is being actively exploited in the wild according to Fortinet. Versions 3.21.21 through before 3.30.2 are affected, with a CVSS v3.1 score of 9.8, allowing remote attackers to achieve full code execution without authentication.

Technical Analysis

CVE-2026-58138 is an unauthenticated RCE affecting Orkes Conductor versions 3.21.21 up to (but not including) 3.30.2, rated 9.8 (CVSS v3.1) and 9.3 (CVSS v4). Conductor exposes workflow definition and task execution APIs; the flaw likely stems from insufficient input validation or unsafe deserialization/scripting execution within workflow task handlers, allowing attackers to inject and execute arbitrary code without credentials. Active exploitation has been observed in the wild, indicating attackers have working exploit chains and are scanning for internet-exposed Conductor instances. Because Conductor is frequently used as an orchestration backbone for AI agent pipelines and multi-step LLM tool-calling workflows, a successful compromise could allow attackers to hijack agent task execution, exfiltrate embedded API keys/credentials used by agents, or pivot into connected RAG data stores and downstream systems. Organizations running agent frameworks that rely on Conductor for workflow orchestration face direct risk of full compute takeover on hosts driving their agent logic.

Affected Systems

Orkes Conductor versions 3.21.21 through prior to 3.30.2; self-hosted and cloud deployments exposing the Conductor API/UI to untrusted networks; any AI agent orchestration or workflow automation stack built on top of Conductor.

Indicators of Compromise

  • No specific hashes, IPs, or domains published at time of disclosure; monitor Fortinet and vendor advisories for updated IOC lists.
  • Suspicious outbound connections or process spawning from Conductor server hosts
  • Unexpected workflow definitions or task scripts created via API without corresponding authenticated user session

Remediation Steps

  1. 1

    Patch immediately

    Upgrade Orkes Conductor to version 3.30.2 or later, which remediates CVE-2026-58138.

  2. 2

    Restrict network exposure

    Ensure Conductor management APIs and UI are not exposed to the public internet; place behind VPN, firewall, or zero-trust access controls.

  3. 3

    Audit for compromise

    Review Conductor server logs for unauthenticated API calls, unexpected workflow/task creation, and anomalous process execution since the vulnerability disclosure window.

  4. 4

    Rotate credentials

    Rotate any API keys, service account credentials, or secrets accessible to or stored within Conductor workflows, especially those used by connected AI agents or LLM tool integrations.

  5. 5

    Enable authentication and monitoring

    Enforce strong authentication on all Conductor endpoints and enable detailed audit logging/alerting for workflow execution API activity.

CVE / Advisory IDs

CVE-2026-58138

Industries Most Exposed

TechnologySoftware DevelopmentFinancial ServicesE-commerceHealthcareTelecommunicationsAny industry using AI agent/workflow automation platforms

Sources

Respond to this threat

Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.