Critical Orkes Conductor flaw reportedly exploited in attacks
SecurityWeek says CVE-2026-58138 lets attackers execute code remotely without authentication through inline workflow definitions.
TLDR
SecurityWeek reports that attackers have exploited a critical vulnerability in Orkes Conductor. The flaw, tracked as CVE-2026-58138, enables remote code execution without authentication via inline workflow definitions.
Combined views
2.3K
1 Source, first seen 13h ago
Critical Orkes Conductor flaw reportedly exploited in attacks
SecurityWeek says CVE-2026-58138 lets attackers execute code remotely without authentication through inline workflow definitions.
TLDR
SecurityWeek reports that attackers have exploited a critical vulnerability in Orkes Conductor. The flaw, tracked as CVE-2026-58138, enables remote code execution without authentication via inline workflow definitions.