Orkes Conductor에서 원격 코드 실행 취약점이 발생했다.
Fortinet에 따르면 Orkes Conductor의 CVE-2026-58138 취약점이 실제로 악용되고 있다. 이 취약점은 인증되지 않은 상태에서 원격 코드 실행을 허용하며, CVSS v3.1 점수는 9.8, v4 점수는 9.3에 달한다. Orkes Conductor 3.21.21 이전 버전에서 문제를 일으킨다.
A critical RCE vulnerability in Orkes Conductor is being exploited in the wild.
According to Fortinet, a critical vulnerability CVE-2026-58138 in Orkes Conductor is being actively exploited. This vulnerability relates to unauthenticated remote code execution with a CVSS v3.1 score of 9.8 and a v4 score of 9.3. The issue affects versions prior to 3.30.2.