Skip to content

Critical Orkes Conductor Vulnerability Exploited in Attacks

CVE-2026-58138 is an unauthenticated remote code execution vulnerability that attackers can exploit via inline workflow definitions. The post Critical Orkes Conductor Vulnerability Exploited in Attacks appeared first on SecurityWeek.

A critical-severity vulnerability in Orkes Conductor that can be exploited without authentication has been in attackers’ crosshairs for at least a month.

Conductor is an open source unified enterprise framework that allows organizations to orchestrate microservices, workflows, and AI agents.

Tracked as CVE-2026-58138 (CVSS score of 9.8), the critical bug is described as a remote code execution issue exploitable via inline workflow definitions submitted to the workflow API endpoint.

Source: https://www.securityweek.com/critical-orkes-conductor-vulnerability-exploited-in-attacks/

Related breach coverage