A critical unauthenticated remote code execution vulnerability tracked as CVE-2026-58138 in the Orkes Conductor workflow orchestration platform is actively exploited in the wild, with confirmation from Fortinet. The flaw carries a CVSS v3.1 score of 9.8 and a CVSS v4 score of 9.3, placing it among the highest-severity vulnerability classes. Affected versions span Orkes Conductor 3.21.21 through 3.30.1, with version 3.30.2 containing the patch.
Attackers are exploiting the vulnerability via inline workflow definitions, a mechanism that allows arbitrary code execution without any prior authentication. The absence of an authentication requirement means any network-accessible instance of Orkes Conductor is potentially reachable by a threat actor with no credentials, dramatically lowering the barrier to initial exploitation. Organisations running exposed or internet-facing deployments face the highest risk.
With active exploitation confirmed, remediation is time-critical. Security teams should prioritise patching to version 3.30.2 immediately and audit exposed instances for signs of compromise, particularly looking for unusual workflow execution activity or unexpected outbound connections.
Each brief contains detailed narrative, impact assessments, technical analysis, IOCs and response recommendations, all available inside the Deltabridge platform.
We use analytics cookies to understand how visitors use Deltabridge and improve the site. They’re off until you accept. See our Privacy Policy.