CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2026-58138

Critical · CVSS 9.8

Orkes Conductor — Unauthenticated Remote Code Execution via unsandboxed GraalVM script evaluation

CVSS
9.8
nvd
EPSS
KEV
No
Class
oss containerizable
CWE-94

Description

Orkes Conductor 3.21.21 before 3.30.2 contains an unauthenticated remote code execution vulnerability that allows remote attackers to execute arbitrary OS commands by submitting inline workflow definitions containing malicious JavaScript or Python expressions to the workflow API endpoint prior to authentication. Attackers can exploit unsandboxed GraalVM evaluators configured with HostAccess.ALL or allowAllAccess(true) through INLINE, LAMBDA, DO_WHILE, and SWITCH task types to invoke arbitrary system commands via Java reflection or direct subprocess calls.

Search profile — drives PoC discovery

Symbols HostAccess.ALLallowAllAccess(true)INLINELAMBDADO_WHILESWITCHGraalVMworkflow API endpointinline workflow definitionsJavaScriptPythonJava reflectionsubprocess
Keywords CVE-2026-58138Orkes Conductor RCEConductor GraalVM unauthenticated RCEConductor INLINE task RCEConductor LAMBDA task exploitConductor workflow API RCEGraalVM HostAccess.ALL exploitallowAllAccess RCE Conductorconductor-oss CVEOrkes Conductor pre-auth RCEConductor DO_WHILE SWITCH task code execution
Versions: 3.21.21 before 3.30.2

Ranked PoCs (3) — best first

Heuristic ranking — not yet expert-vetted. Scored on structure + provenance, not execution.

Recall-favoring discovery; ranking by the Stage-4 scorer (Adam's rubric). Scanner/aggregator repos are hidden.

References

Status: enriched · ingested 2026-07-15T00:00:20.000Z · profiled 2026-07-15T00:30:20.000Z