OS Command Injection in Progress Software Autonomous REST Connector GenAI Agents
CVE-2026-91140

9.6CRITICAL

What is CVE-2026-91140?

The vulnerability in Progress Software's Autonomous REST Connector GenAI Agents, specifically in the ARCGenAI-Generator version 2.0, allows an attacker to exploit shell-based temporary-file cleanup instructions. By submitting a specially crafted Swagger/OpenAPI document, an attacker can execute arbitrary commands on the developer's machine upon invocation of the generator. This raises significant security concerns, making it crucial for users to apply the latest patches and follow vendor advisories to mitigate potential risks.

Affected Version(s)

Autonomous REST Connector GenAI Agents 2.0 < 2.1

References

CVSS V3.1

Score:
9.6
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Abhishek Nandkumar Bhaskar (Abhi-Hackz)
.