Critical Orkes Conductor vulnerability exploited in attacks
Summary
A critical vulnerability in Orkes Conductor, a platform that enables workflow management, has been actively exploited by attackers, leading to real-world incidents involving unauthorized remote code execution. This flaw allows attackers to execute malicious expressions in workflow definitions through unsandboxed GraalVM evaluators, presenting a significant security risk for exposed instances of the software.
Analysis
Orkes: Orkes develops and maintains an enterprise-grade workflow orchestration platform based on the open-source Conductor project originally created at Netflix. It offers managed cloud services and tools for building durable, scalable workflows across microservices, APIs, and AI agents. Orkes Conductor is the subject of the reported critical vulnerability that has been exploited in attacks. Exploitation: Attackers have been observed actively exploiting the vulnerability in real-world incidents targeting exposed instances. Vulnerability: The flaw in Orkes Conductor allows unauthenticated remote code execution through malicious expressions in workflow definitions using unsandboxed GraalVM evaluators.
Categories
tech
Related sources
- https://cvefeed.io/vuln/detail/CVE-2026-58138
- https://www.vulncheck.com/advisories/orkes-conductor-unauthenticated-rce-via-graalvm-script-evaluators
- https://techcrunch.com/2024/02/21/orkes-raises-20m-series-a/
- https://nvd.nist.gov/vuln/detail/CVE-2026-58138
- https://www.securityweek.com/orkus-exits-stealth-mode-cloud-security-platform/
- https://pitchbook.com/profiles/company/492976-18
- https://www.securityweek.com/this-key-will-self-destruct-an-open-standard-for-revocable-api-keys/
- https://orkes.io/content/category/getting-started
- https://kevintel.com/CVE-2026-58138
- https://orkes.io/about-us
- https://dbugs.ptsecurity.com/vulnerability/PT-2026-53941
- https://yespress.io/orkes
- https://www.securityweek.com/cyber-insights-2023-ics-and-operational-technology/