CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Called exploited 27 days after disclosure.
Measured from the CVE publication date to the earliest of 1 KEV catalogue that list it.
The life of this vulnerability
- CVE published
- First KEV listing27d
- Last sighting40d
Gaps are compressed to equal steps. The elapsed time is printed under each.
Which catalogues call it exploited
- CISA KEVUS federaldoes not list it
- EUVDENISA, European Uniondoes not list it
- VulnCheck KEVcommercial researchlisted Jul 27, 2026
- CIRCLaggregator, mirrors the abovelisted Jul 27, 2026, not counted
This rests on a single catalogue. No second catalogue corroborates the claim that it is being exploited. CIRCL is an aggregator and is not counted.
Public exploitation evidence
- reported exploitationapi.vulncheck.com/v3/index/vulncheck-canaries?cve=CVE-2026-5
- reported exploitationapi.vulncheck.com/v3/index/vulncheck-canaries?cve=CVE-2026-5
- reported exploitationapi.vulncheck.com/v3/index/vulncheck-canaries?cve=CVE-2026-5
- reported exploitationapi.vulncheck.com/v3/index/vulncheck-canaries?cve=CVE-2026-5
- reported exploitationapi.vulncheck.com/v3/index/vulncheck-canaries?cve=CVE-2026-5
- reported exploitationapi.vulncheck.com/v3/index/vulncheck-canaries?cve=CVE-2026-5
16 public reports collected from VulnCheck and CIRCL, first on Jul 27, 2026. Each links to its original source. We have not verified them.
Description
Orkes Conductor 3.21.21 before 3.30.2 contains an unauthenticated remote code execution vulnerability that allows remote attackers to execute arbitrary OS commands by submitting inline workflow definitions containing malicious JavaScript or Python expressions to the workflow API endpoint prior to authentication. Attackers can exploit unsandboxed GraalVM evaluators configured with HostAccess.ALL or allowAllAccess(true) through INLINE, LAMBDA, DO_WHILE, and SWITCH task types to invoke arbitrary system commands via Java reflection or direct subprocess calls.
