Unpatched Orkes Conductor Servers Under Attack From Critical Pre‑Auth Remote Code Execution Flaw
Attackers are exploiting a critical pre‑authentication remote code execution vulnerability in Orkes Conductor by submitting crafted workflow definitions with malicious JavaScript or Python expressions. Nearly 7,000 attack attempts were blocked between 2 and 9 September, and admins are urged to upgrade to version 3.30.2 or later.
A serious bug in Orkes Conductor is letting attackers try to run their own code on servers without needing to log in first.
Security researchers report active exploitation of a critical pre‑authentication remote code execution vulnerability in Orkes Conductor, a workflow orchestration platform. The exploit involves sending crafted workflow definitions that contain malicious JavaScript or Python expressions, which the vulnerable server then evaluates.
From 2 to 9 September, nearly 7,000 attack attempts targeting this flaw were blocked, according to technical reporting. That volume points to automated scanning and broad interest from attackers, not just isolated testing.
Because the vulnerability works before authentication, anyone who can reach an exposed Orkes Conductor instance can try to abuse it. In many environments, Conductor sits at the centre of back‑end processes, so successful code execution there could open paths deeper into internal systems.
The advised mitigation is straightforward: upgrade Orkes Conductor to version 3.30.2 or later, which contains a fix. Organisations running earlier versions, especially on internet‑accessible servers, face an elevated risk until they patch or restrict access.
Security teams should watch for suspicious workflow submissions, confirm their Conductor version, and treat this as a priority update given the level of scanning already observed.
Sources
- OSINT