A critical remote code execution vulnerability in the Orkes Conductor workflow orchestration platform is being actively exploited in the wild, according to Fortinet. The flaw, tracked as CVE-2026-58138, carries a CVSS v3.1 score of 9.8 and a CVSS v4 score of 9.3, placing it among the most severe classes of vulnerabilities.
The bug affects Orkes Conductor versions 3.21.21 through versions prior to 3.30.2. It allows an unauthenticated remote attacker to achieve arbitrary code execution on affected systems, meaning no valid credentials or prior access are required to exploit it.
Why It Matters
Orkes Conductor is used by organizations to orchestrate and manage distributed workflows and microservices. A pre-authentication RCE in this type of platform is particularly dangerous because it can serve as a direct entry point into backend infrastructure, potentially exposing connected services, data pipelines, and orchestration logic to compromise.
Because the vulnerability requires no authentication, any internet-facing or improperly segmented instance of the affected versions is at immediate risk. Fortinet’s observation of active exploitation indicates that threat actors have already developed working exploits and are targeting vulnerable deployments in real-world attacks.
Recommended Actions
- Identify all instances of Orkes Conductor running versions between 3.21.21 and prior to 3.30.2.
- Upgrade to version 3.30.2 or later as soon as possible to remediate the vulnerability.
- Restrict network exposure of Conductor instances, ensuring they are not directly reachable from the public internet where not required.
- Monitor logs and network traffic for signs of exploitation attempts or unauthorized access tied to this vulnerability.
Given the critical severity and confirmed in-the-wild exploitation, security teams running Orkes Conductor should treat patching as an urgent priority.
