Skip to content
Critical Vulnerability in Progress DataDirect ARCGenAI Agents Disclosed

Critical Vulnerability in Progress DataDirect ARCGenAI Agents Disclosed

First seen 7 Oct 2026, 07:27 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •October 7, 2026 at 07:28 UTC
  • •CVE-2026-91140 has a CVSS score of 9.6, indicating a critical vulnerability.
  • •The vulnerability allows arbitrary command execution on developer machines via unvalidated filenames.
  • •Progress Software has released a patch, but no exploitation has been confirmed in the wild.

Progress Software disclosed a critical vulnerability (CVE-2026-91140) in its DataDirect Autonomous REST Connector GenAI Agents on October 6, 2026. The flaw, with a CVSS score of 9.6, allows attackers to execute arbitrary OS commands via crafted OpenAPI or Swagger documents containing shell metacharacters in filenames. This vulnerability is part of a broader trend of supply-chain vulnerabilities where AI agents treat configuration specifications as trusted input. Progress has released a patch in version 2.1 of the agent definitions. No in-the-wild exploitation or public proof-of-concept exists at the time of disclosure. This incident highlights a structural failure in how AI agents process input, similar to previous vulnerabilities documented earlier in 2026. The lack of automated compliance checks and security certification standards exacerbates the risk associated with these vulnerabilities.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2025-08-01
CVE-2025-54136 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2025-08-05
CVE-2025-54135 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2025-08-12
CVE-2025-53773 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-10-06
CVE-2026-91140 published
Progress Software disclosed a critical vulnerability in its DataDirect ARCGenAI Agents, allowing arbitrary command execution.
Tech.Yahoo
2026-10-07
Patch released for vulnerability
Progress Software released version 2.1 of the agent definitions to address CVE-2026-91140.
Tech.Yahoo

More articles in this cluster (5)

Following this threat?

Track Progress Software and CVE-2025-53773 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed

Common questions

What is CVE-2026-91140?
CVE-2026-91140 is a critical vulnerability in Progress DataDirect ARCGenAI Agents that allows arbitrary command execution.
Has this vulnerability been exploited in the wild?
No, there have been no confirmed reports of exploitation in the wild as of the disclosure.
What should I do if I'm using ARCGenAI Agents?
Upgrade to version 2.1 of the agent definitions to mitigate the vulnerability.