Progress security advisory (AV26-1005)
Canada's Cyber Centre warns of CVE-2026-91140 in Progress ARCGenAI-Generator before version 2.1.
The Canadian Centre for Cyber Security issued advisory AV26-1005 on October 6, 2026, for a vulnerability in Progress Software's Autonomous REST Connector GenAI Agents component, ARCGenAI-Generator, before version 2.1. The notice points to Progress's September 2026 DataDirect critical security alert for CVE-2026-91140 and urges administrators to review the vendor guidance and apply updates. The bulletin does not report active exploitation.
- Advisory AV26-1005 covers ARCGenAI-Generator before version 2.1.
- The issue is tracked as CVE-2026-91140.
- No active exploitation is reported; users should update.
Vulnerabilities mentionedAll →
- CVE-2026-911409.6—OS Command Injection via Malicious OpenAPI Docs in Progress ARCGenAI-Generator 2.0published · Progress Software Autonomous REST Connector GenAI Agents ARCGenAI-Generator
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-91140 | OS Command Injection via Malicious OpenAPI Docs in Progress ARCGenAI-Generator 2.0 Progress Software's Autonomous REST Connector GenAI Agents ARCGenAI-Generator version 2.0 contains an OS command injection flaw (CWE-78) in the shell-based temporary-file cleanup instructions it executes during code generation. An attacker crafts a malicious Swagger/OpenAPI document and gets a developer to run the generator against it; when the generator is invoked, attacker-controlled input reaches a shell command and arbitrary commands execute on the developer's machine. Successful exploitation gives full control of the victim workstation or CI runner (high impact to confidentiality, integrity, and availability, with scope escape beyond the tool itself), which can expose source code, credentials, and source-control or pipeline access. Only users who feed untrusted OpenAPI specifications into ARCGenAI-Generator 2.0 are exposed. There is no known public proof of concept, it is not in CISA's KEV catalog, and no exploitation has been observed. |
Full article70 words · extracted from cyber.gc.ca · click to collapse
Serial number: AV26-1005
Date: October 6, 2026
As of October 6, 2026, Progress Software is affected by a vulnerability in the following product:
- Progress Software Autonomous REST Connector GenAI Agents ARCGenAI-Generator
- Prior to 2.1
The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyber.gc.ca/en/alerts-advisories/progress-security-advisory-av26-1005