CVE-2026-58138 — Conductor (3.21.21..<3.30.2) unauthenticated RCE via INLINE GraalVM evaluator (HostAccess.ALL). Lab + PoC, verified e2e (root).
proof-of-concept exploit cybersecurity poc rce bug-bounty graalvm conductor code-injection red-team security-research unauthenticated vulnerability-research remote-code-execution netflix-conductor orkes-conductor sandbox-bypass python-exploit cve-2026-58138 cwe-94
-
Updated
Jul 15, 2026 - Python