Progress disclosed critical command injection flaw CVE-2026-91140 in DataDirect Autonomous REST Connector AI Model Generator agents, allowing malicious OpenAPI or Swagger documents to execute arbitrary OS commands. The security bulletin, published on October 6, 2026, covers Early Access agent definitions available through the public progress/datadirect-arc-ai-model-gen GitHub repository. Progress has released updated definitions and urges customers […]
Read the original article:
