Critical Pre-Auth RCE in Orkes Conductor Workflow Platform Exploited in the Wild
If you run Orkes Conductor, there goes your weekend. CVE-2026-58138 (CVSS 9.8) lets an unauthenticated request submit a workflow whose INLINE or LAMBDA task carries JavaScript — and the GraalVM evaluator is configured with allowAllAccess(true), so it executes with the Conductor process’s privileges. Fortinet blocked nearly 7,000 attempts in one week. Fixed in 3.30.2; 3.21.21 through 3.30.1 are exposed.