cvemon logocvemon logo

Activity

Trending

CVE-2025-26074

Published Jun 30, 2025

Last updated 18 days ago

  1. Overview

  2. Social media

  3. References

Overview

Description
Orkes Conductor v3.21.11 allows remote attackers to execute arbitrary OS commands through unrestricted access to Java classes.
Source
cve@mitre.org
NVD status
Awaiting Analysis

Social media

Hype score
Not currently trending
  1. CVE-2025-26074 Orkes Conductor v3.21.11 allows remote attackers to execute arbitrary OS commands through unrestricted access to Java classes. https://t.co/pp6dceWC6r

    @CVEnew

    30 Jun 2025

    14 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

References

Sources include official advisories and independent security research.

  • https://nvd.nist.gov/vuln/detail/CVE-2025-26074
  • https://github.com/conductor-oss/conductor
  • https://github.com/conductor-oss/conductor/blob/main/core/src/main/java/com/netflix/conductor/core/events/ScriptEvaluator.java
  • https://medium.com/@mrcnry/cve-2025-26074-remote-code-execution-in-conductor-oss-via-inline-javascript-injection-5ce3cb651cfb
TRY INTRUDER
Intruder logo

© 2025 Intruder Systems Ltd.

AboutPrivacySitemapFeeds