Critical Progress DataDirect GenAI Flaw Lets Attackers Execute Arbitrary OS Commands

Progress has disclosed a critical command injection vulnerability in the Early Access Release of its DataDirect Autonomous REST Connector AI Model Generator agents. This vulnerability, tracked as CVE-2026-91140, allows specially crafted OpenAPI or Swagger documents to execute arbitrary operating system commands within the environment running an affected agent. The security bulletin, dated October 6, 2026, […]

This article has been indexed from GBHackers Security | #1 Globally Trusted Cyber Security News Platform

Read the original article: