Attackers are actively exploiting a critical remote-code-execution vulnerability in the Orkes Conductor workflow platform. The flaw, tracked as CVE-2026-58138, affects versions 3.21.21 through releases before 3.30.2 and can be reached without authentication.
Fortinet reported exploitation in the wild, with SecurityWeek also reporting that the vulnerability is being used in attacks, as first reported by The Hacker News. The issue carries a 9.8 score under CVSS v3.1 and a 9.3 score under the newer CVSS v4 system.
Inline workflow definitions create the attack path
CVE-2026-58138 can allow an unauthenticated remote attacker to execute code through workflow-related functionality. Inline workflow definitions provide the known route for triggering the weakness, allowing an attacker to target a vulnerable deployment remotely rather than first obtaining a valid account.
Orkes Conductor is used to run and coordinate workflows, making the flaw especially urgent for organizations with exposed instances. Remote code execution can give an intruder control over the affected system, while the lack of an authentication requirement removes a significant barrier that would otherwise limit access.
The version range also gives administrators a concrete starting point for incident response. Teams operating Conductor should establish which release they run, determine whether inline workflow definitions are available in their environment, and review systems for signs of unauthorized activity.
The reported exploitation raises the priority
Critical software flaws often require rapid attention, but reported in-the-wild use changes the calculation. This is no longer solely a theoretical weakness that defenders can schedule into a routine maintenance window; attackers have reportedly incorporated it into real attacks against an enterprise workflow platform.
Several important details remain unconfirmed. Public reporting has not identified the attackers, disclosed how many organizations or systems may be affected, or described the timeline and impact of the observed attacks. The available information also does not establish whether a remediation beyond version 3.30.2 is available.
This article was produced with AI assistance from multi-source reporting and is published under our editorial standards.