Orkes Conductor 3.21.21 before 3.30.2 contains an unauthenticated remote code execution vulnerability that allows remote attackers to execute arbitrary OS commands by submitting inline workflow definitions containing malicious JavaScript or Python expressions to the workflow API endpoint prior to authentication. Attackers can exploit unsandboxed GraalVM evaluators configured with HostAccess.ALL or allowAllAccess(true) through INLINE, LAMBDA, DO_WHILE, and SWITCH task types to invoke arbitrary system commands via Java reflection or direct subprocess calls.
{
"cna_assigner": "VulnCheck",
"cwe_ids": [
"CWE-94"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/58xxx/CVE-2026-58138.json"
}"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-58138.json"
[
{
"deprecated": false,
"digest": {
"function_hash": "84148849741505566429337688419395115555",
"length": 158
},
"id": "CVE-2026-58138-0a774026",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/conductor-oss/conductor/commit/87a7d96aabbb706d6e84f812b93da5165028d18f",
"target": {
"file": "core/src/main/java/com/netflix/conductor/core/events/ScriptEvaluator.java",
"function": "createNewContext"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"338428174764023973727634848859948519761",
"326689129891890834693720027258177309217",
"223977315390620034619533889416219123560"
],
"threshold": 0.9
},
"id": "CVE-2026-58138-1da7e5ac",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/conductor-oss/conductor/commit/c691e35e768caeb802c9f06ecdd9674c80081af1",
"target": {
"file": "core/src/test/java/com/netflix/conductor/core/execution/tasks/InlineTest.java"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"177424437706388046767459938608702658108",
"158573321384187060201756415068846944419",
"172489535149810717856306506944481035715",
"36039605343112477419356437383947553018",
"28300461141751643948482032749468040842",
"25938867571625038949570063114878726440"
],
"threshold": 0.9
},
"id": "CVE-2026-58138-24a44b79",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/conductor-oss/conductor/commit/87a7d96aabbb706d6e84f812b93da5165028d18f",
"target": {
"file": "core/src/main/java/com/netflix/conductor/core/events/ScriptEvaluator.java"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"14263073375674915010106411337580871702",
"336092008055508189533848680117021579665",
"73009250532504344247427321444711438441",
"231358558825251465045483672517279575302"
],
"threshold": 0.9
},
"id": "CVE-2026-58138-35a52f17",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/conductor-oss/conductor/commit/87a7d96aabbb706d6e84f812b93da5165028d18f",
"target": {
"file": "core/src/main/java/com/netflix/conductor/core/execution/evaluators/PythonEvaluator.java"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "337924285897608416776875093268798677825",
"length": 1152
},
"id": "CVE-2026-58138-35cbe0d2",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/conductor-oss/conductor/commit/87a7d96aabbb706d6e84f812b93da5165028d18f",
"target": {
"file": "core/src/main/java/com/netflix/conductor/core/execution/evaluators/PythonEvaluator.java",
"function": "evaluate"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"331450159162433067306863347955740651542",
"234821517644514556049047479668761062371",
"334545837011759910128507200347764233282",
"167259593701159649616931797476525725314",
"43269489771517835694642460880919301486",
"212286992827027389176658257572483332293",
"160552539653032825829838744138421182892",
"177867605583130446814341781763932278203",
"279283374030730091602252445010988106049",
"20951446462807220320183328566693115279",
"294317454698469958456875044020387557499",
"134489705437900885133330243896962251500",
"61873553322891618935755170042630690426",
"49744472518247248328467298851517023831"
],
"threshold": 0.9
},
"id": "CVE-2026-58138-82942ec9",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/conductor-oss/conductor/commit/c691e35e768caeb802c9f06ecdd9674c80081af1",
"target": {
"file": "core/src/main/java/com/netflix/conductor/core/events/ScriptEvaluator.java"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"195624456621598581744504188171879724513",
"48647700149042129477010075910635951063",
"278633147127277620058703112894294746408",
"57332886043347968002740591871700739496",
"14211301237228803010485783334874071809",
"223977315390620034619533889416219123560"
],
"threshold": 0.9
},
"id": "CVE-2026-58138-8b964ec7",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/conductor-oss/conductor/commit/87a7d96aabbb706d6e84f812b93da5165028d18f",
"target": {
"file": "core/src/test/java/com/netflix/conductor/core/execution/tasks/InlineTest.java"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "304307455328021354749768653624044329698",
"length": 523
},
"id": "CVE-2026-58138-a73898ee",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/conductor-oss/conductor/commit/c691e35e768caeb802c9f06ecdd9674c80081af1",
"target": {
"file": "core/src/main/java/com/netflix/conductor/core/events/ScriptEvaluator.java",
"function": "createNewContext"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "271398121919177059945044607773590055812",
"length": 267
},
"id": "CVE-2026-58138-ca53eb61",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/conductor-oss/conductor/commit/c691e35e768caeb802c9f06ecdd9674c80081af1",
"target": {
"file": "core/src/main/java/com/netflix/conductor/core/events/ScriptEvaluator.java",
"function": "buildEngine"
}
}
]
"2026-08-12T16:09:51Z"