Critical Pre-Auth RCE in Orkes Conductor Workflow Platform Exploited in the Wild
Summary
A critical pre-authentication remote code execution vulnerability, identified as CVE-2026-58138, has been discovered in the Orkes Conductor workflow platform and is reportedly being exploited in the wild. Fortinet has reported on this flaw, highlighting its severity.
IFF Assessment
FOE
This vulnerability allows for unauthenticated remote code execution, posing a significant threat to systems using the Orkes Conductor platform.
Severity
9.8
Critical
Defender Context
Defenders should be aware of active exploitation of CVE-2026-58138 in Orkes Conductor. Prioritizing patching or implementing compensating controls for this vulnerability is crucial to prevent unauthorized code execution on their systems. Monitoring for any signs of compromise related to this specific exploit should be a high priority.