{"id":"CVE-2026-58138","summary":"Orkes Conductor 3.21.21 \u003c 3.30.2 Unauthenticated RCE via GraalVM Script Evaluators","details":"Orkes Conductor 3.21.21 before 3.30.2 contains an unauthenticated remote code execution vulnerability that allows remote attackers to execute arbitrary OS commands by submitting inline workflow definitions containing malicious JavaScript or Python expressions to the workflow API endpoint prior to authentication. Attackers can exploit unsandboxed GraalVM evaluators configured with HostAccess.ALL or allowAllAccess(true) through INLINE, LAMBDA, DO_WHILE, and SWITCH task types to invoke arbitrary system commands via Java reflection or direct subprocess calls.","modified":"2026-08-12T16:09:51.720206Z","published":"2026-06-30T18:44:12.734Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/58xxx/CVE-2026-58138.json","cna_assigner":"VulnCheck","cwe_ids":["CWE-94"]},"references":[{"type":"WEB","url":"https://www.cve.org/CVERecord?id=CVE-2025-26074"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/58xxx/CVE-2026-58138.json"},{"type":"ADVISORY","url":"https://github.com/conductor-oss/conductor/releases/tag/v3.30.2"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-58138"},{"type":"ADVISORY","url":"https://www.vulncheck.com/advisories/orkes-conductor-unauthenticated-rce-via-graalvm-script-evaluators"},{"type":"FIX","url":"https://github.com/conductor-oss/conductor/commit/87a7d96aabbb706d6e84f812b93da5165028d18f"},{"type":"FIX","url":"https://github.com/conductor-oss/conductor/commit/c691e35e768caeb802c9f06ecdd9674c80081af1"},{"type":"PACKAGE","url":"https://github.com/conductor-oss/conductor"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/conductor-oss/conductor","events":[{"introduced":"b9f50bbcc6ed9b8f3f8de2aacec9974b55abcca4"},{"fixed":"2bea5078f916c0d529cd0f32a55f79425b65a5b8"},{"fixed":"87a7d96aabbb706d6e84f812b93da5165028d18f"},{"fixed":"c691e35e768caeb802c9f06ecdd9674c80081af1"}],"database_specific":{"extracted_events":[{"introduced":"3.21.21"},{"fixed":"3.30.2"}],"source":["DESCRIPTION","REFERENCES"]}}],"versions":["v3.30.0.rc16","v3.30.0.rc3","v3.31.0-rc.1","v3.30.1","v3.30.0.rc18","v3.30.0","v3.30.0.rc17","v3.30.0.rc15","v3.30.0.rc14","v3.30.0.rc13","v3.30.0.rc12","v3.30.0.rc10","v3.30.0.rc9","v3.30.0.rc7","v3.30.0.rc6","v3.30.0.rc5","v3.30.0.rc4","v3.30.0.rc2","v3.30.0.rc1","v3.3.0.rc8","v3.3.0.rc7","v3.3.0.rc6","v3.3.0.rc5","v3.3.0.rc4","v3.3.0.rc3","v3.23.0","v3.22.3","v3.22.2","v3.22.1","v3.22.0","v3.22.0-beta","v3.21.24-rc.1","v3.21.23","v3.21.22","v3.21.21"],"database_specific":{"vanir_signatures":[{"id":"CVE-2026-58138-0a774026","signature_type":"Function","signature_version":"v1","source":"https://github.com/conductor-oss/conductor/commit/87a7d96aabbb706d6e84f812b93da5165028d18f","target":{"file":"core/src/main/java/com/netflix/conductor/core/events/ScriptEvaluator.java","function":"createNewContext"},"deprecated":false,"digest":{"function_hash":"84148849741505566429337688419395115555","length":158}},{"source":"https://github.com/conductor-oss/conductor/commit/c691e35e768caeb802c9f06ecdd9674c80081af1","target":{"file":"core/src/test/java/com/netflix/conductor/core/execution/tasks/InlineTest.java"},"deprecated":false,"digest":{"threshold":0.9,"line_hashes":["338428174764023973727634848859948519761","326689129891890834693720027258177309217","223977315390620034619533889416219123560"]},"id":"CVE-2026-58138-1da7e5ac","signature_type":"Line","signature_version":"v1"},{"signature_type":"Line","signature_version":"v1","source":"https://github.com/conductor-oss/conductor/commit/87a7d96aabbb706d6e84f812b93da5165028d18f","target":{"file":"core/src/main/java/com/netflix/conductor/core/events/ScriptEvaluator.java"},"deprecated":false,"digest":{"line_hashes":["177424437706388046767459938608702658108","158573321384187060201756415068846944419","172489535149810717856306506944481035715","36039605343112477419356437383947553018","28300461141751643948482032749468040842","25938867571625038949570063114878726440"],"threshold":0.9},"id":"CVE-2026-58138-24a44b79"},{"deprecated":false,"digest":{"threshold":0.9,"line_hashes":["14263073375674915010106411337580871702","336092008055508189533848680117021579665","73009250532504344247427321444711438441","231358558825251465045483672517279575302"]},"id":"CVE-2026-58138-35a52f17","signature_type":"Line","signature_version":"v1","source":"https://github.com/conductor-oss/conductor/commit/87a7d96aabbb706d6e84f812b93da5165028d18f","target":{"file":"core/src/main/java/com/netflix/conductor/core/execution/evaluators/PythonEvaluator.java"}},{"target":{"file":"core/src/main/java/com/netflix/conductor/core/execution/evaluators/PythonEvaluator.java","function":"evaluate"},"deprecated":false,"digest":{"function_hash":"337924285897608416776875093268798677825","length":1152},"id":"CVE-2026-58138-35cbe0d2","signature_type":"Function","signature_version":"v1","source":"https://github.com/conductor-oss/conductor/commit/87a7d96aabbb706d6e84f812b93da5165028d18f"},{"deprecated":false,"digest":{"line_hashes":["331450159162433067306863347955740651542","234821517644514556049047479668761062371","334545837011759910128507200347764233282","167259593701159649616931797476525725314","43269489771517835694642460880919301486","212286992827027389176658257572483332293","160552539653032825829838744138421182892","177867605583130446814341781763932278203","279283374030730091602252445010988106049","20951446462807220320183328566693115279","294317454698469958456875044020387557499","134489705437900885133330243896962251500","61873553322891618935755170042630690426","49744472518247248328467298851517023831"],"threshold":0.9},"id":"CVE-2026-58138-82942ec9","signature_type":"Line","signature_version":"v1","source":"https://github.com/conductor-oss/conductor/commit/c691e35e768caeb802c9f06ecdd9674c80081af1","target":{"file":"core/src/main/java/com/netflix/conductor/core/events/ScriptEvaluator.java"}},{"source":"https://github.com/conductor-oss/conductor/commit/87a7d96aabbb706d6e84f812b93da5165028d18f","target":{"file":"core/src/test/java/com/netflix/conductor/core/execution/tasks/InlineTest.java"},"deprecated":false,"digest":{"line_hashes":["195624456621598581744504188171879724513","48647700149042129477010075910635951063","278633147127277620058703112894294746408","57332886043347968002740591871700739496","14211301237228803010485783334874071809","223977315390620034619533889416219123560"],"threshold":0.9},"id":"CVE-2026-58138-8b964ec7","signature_type":"Line","signature_version":"v1"},{"signature_version":"v1","source":"https://github.com/conductor-oss/conductor/commit/c691e35e768caeb802c9f06ecdd9674c80081af1","target":{"file":"core/src/main/java/com/netflix/conductor/core/events/ScriptEvaluator.java","function":"createNewContext"},"deprecated":false,"digest":{"function_hash":"304307455328021354749768653624044329698","length":523},"id":"CVE-2026-58138-a73898ee","signature_type":"Function"},{"deprecated":false,"digest":{"function_hash":"271398121919177059945044607773590055812","length":267},"id":"CVE-2026-58138-ca53eb61","signature_type":"Function","signature_version":"v1","source":"https://github.com/conductor-oss/conductor/commit/c691e35e768caeb802c9f06ecdd9674c80081af1","target":{"file":"core/src/main/java/com/netflix/conductor/core/events/ScriptEvaluator.java","function":"buildEngine"}}],"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-58138.json","vanir_signatures_modified":"2026-08-12T16:09:51Z"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"}]}