OS Command Injection in Progress Software Autonomous REST Connector GenAI Agents
CVE-2026-91140
9.6CRITICAL
Key Information:
- Vendor
Progress Software
- Vendor
- CVE Published:
- 6 October 2026
What is CVE-2026-91140?
The vulnerability in Progress Software's Autonomous REST Connector GenAI Agents, specifically in the ARCGenAI-Generator version 2.0, allows an attacker to exploit shell-based temporary-file cleanup instructions. By submitting a specially crafted Swagger/OpenAPI document, an attacker can execute arbitrary commands on the developer's machine upon invocation of the generator. This raises significant security concerns, making it crucial for users to apply the latest patches and follow vendor advisories to mitigate potential risks.
Affected Version(s)
Autonomous REST Connector GenAI Agents 2.0 < 2.1