CVE-2026-91140
9.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Summary
An OS command injection vulnerability in the shell-based temporary-file cleanup instructions in Progress Software Autonomous REST Connector GenAI Agents ARCGenAI-Generator version 2.0 allows an attacker who supplies a crafted Swagger/OpenAPI document to execute arbitrary commands on a developer's machine when a user invokes the generator.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Progress Software | Autonomous REST Connector GenAI Agents | 2.0 < 2.1 | affected |
Weaknesses
- CWE-78: CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Workarounds
Upgrade ARCGenAI-Generator to version 2.1 or later. Until the upgrade is applied, do not process untrusted Swagger/OpenAPI documents.
ADP Enrichment
CISA ADP Vulnrichment
- SSVC:
- Exploitation: none
- Automatable: no
- Technical Impact: total
References
- https://github.com/progress/datadirect-arc-ai-model-gen/commit/7ede6d96eb033d647ffdcabf8d8069c098293575
- https://community.progress.com/s/article/Progress-DataDirect-Critical-Security-Alert-Bulletin-September-2026-CVE-2026-91140
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.