Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
5022 articles · 188920 vulns · 37/41 feeds (7d)
← Back to list
9.8
CVE-2026-58138KEVEXPLOITEDPATCHED
conductor-oss · conductor

Orkes Conductor 3.21.21 < 3.30.2 Unauthenticated RCE via GraalVM Script Evaluators

Description

Orkes Conductor 3.21.21 before 3.30.2 contains an unauthenticated remote code execution vulnerability that allows remote attackers to execute arbitrary OS commands by submitting inline workflow definitions containing malicious JavaScript or Python expressions to the workflow API endpoint prior to authentication. Attackers can exploit unsandboxed GraalVM evaluators configured with HostAccess.ALL or allowAllAccess(true) through INLINE, LAMBDA, DO_WHILE, and SWITCH task types to invoke arbitrary system commands via Java reflection or direct subprocess calls.

Affected Products

VendorProductVersions
conductor-ossconductor3.21.21

References

  • https://github.com/conductor-oss/conductor/releases/tag/v3.30.2(release-notes)
  • https://github.com/conductor-oss/conductor/commit/87a7d96aabbb706d6e84f812b93da5165028d18f(patch)
  • https://github.com/conductor-oss/conductor/commit/c691e35e768caeb802c9f06ecdd9674c80081af1(patch)
  • https://www.cve.org/CVERecord?id=CVE-2025-26074
  • https://www.vulncheck.com/advisories/orkes-conductor-unauthenticated-rce-via-graalvm-script-evaluators(third-party-advisory)

Related News (2 articles)

Tier C
Exploit-DB2d ago
[webapps] OrkesConductor 3.30.2 - Unauthenticated Remote Code Execution
→ No new info (linked only)
Tier C
VulDB42d ago
CVE-2026-58138 | conductor-oss conductor up to 3.30.1 Workflow API Endpoint code injection
→ No new info (linked only)
CVSS 3.19.8 NONE
CISA KEV✅ Yes
Actively exploited✅ Yes
Patch available
3.30.2
CWECWE-94
PublishedJun 30, 2026
Last enriched42d agov2
Trending Score77
Source articles2
Independent2
Info Completeness9/14
Missing: epss, kev, exploit, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Jun 30, 2026
Added to CISA KEV
Jun 30, 2026
Discovered by ZDM
Jun 30, 2026
Updated: affectedVersions
Jul 1, 2026
Actively Exploited
Jul 14, 2026
Patch Available
Jul 14, 2026

Version History

v2
Last enriched 42d ago
v2Tier C42d ago

Updated affected versions to include 3.30.1 and clarified that no exploit is available.

affectedVersions
via VulDB
v142d ago

Initial creation