Answer in brief
CVE-2026-91140 records a Critical severity (CVSS 9.6) vulnerability in OS command injection in Progress Software Autonomous REST Connector GenAI Agents. The current sources do not mark it as known exploited. The current feed maps Progress Software/Autonomous REST Connector GenAI Agents (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
CVSS is 9.6. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Progress Software/Autonomous REST Connector GenAI Agents (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Progress Software/Autonomous REST Connector GenAI Agentsgeneric | >=2.0 <2.1 | 2.1 |
Published upstream
Oct 6, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Oct 6, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Oct 6, 2026
An OS command injection vulnerability in the shell-based temporary-file cleanup instructions in Progress Software Autonomous REST Connector GenAI Agents ARCGenAI-Generator version 2.0 allows an attacker who supplies a crafted Swagger/OpenAPI document to execute arbitrary commands on a developer's machine when a user invokes the generator.
Quoted source text, attributed separately from HOL analysis.