Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.6

CVE-2026-91140: Progress Autonomous REST Connector can run unwanted commands

CVE-2026-91140 · published 4 days ago
Summary

The Autonomous REST Connector GenAI Agents version 2.0 can be tricked by a specially crafted API description file to run any command on the developer’s computer during generation. This could let an attacker take control of the machine or steal data. Update to a patched version or stop using untrusted API files until the fix is applied.

What to do
  • Update progress software autonomous rest connector genai agents to version 2.1 or later.
Affected software
VendorProductAffected versions
progress software autonomous rest connector genai agents < 2.1
Original advisory text
OS command injection in Progress Software Autonomous REST Connector GenAI Agents
An OS command injection vulnerability in the shell-based temporary-file cleanup instructions in Progress Software Autonomous REST Connector GenAI Agents ARCGenAI-Generator version 2.0 allows an attacker who supplies a crafted Swagger/OpenAPI document to execute arbitrary commands on a developer's machine when a user invokes the generator.
Fix within
Internet-facing 14 days
Internal At next upgrade
  • Not known to be exploited
  • Needs hands-on effort to exploit
  • Gives an attacker full control
Severity
9.6 Critical
Exploitation
2% chance of attack within 30 days
Type
CWE-78OS Command Injection
Timeline
Published6 Oct 2026
Updated9 Oct 2026
First seen6 Oct 2026
Sources
CVE-2026-91140 · MITRE
Track software like this
Free during beta