# Progress DataDirect GenAI Command Injection via OpenAPI/Swagger Filename (CVE-2026-91140)

> CVE-2026-91140 is a critical (CVSS 9.6) OS command injection in the Progress DataDirect Autonomous REST Connector GenAI agent definitions (ARCGenAI-Generator.agent.md v2.0, ARCGenAI-Generator.prompt.md v1.0, ARCGenAI-EntityGen.agent.md v1.0). A filename derived from a crafted OpenAPI/Swagger document reaches a shell operation without validation or quoting, so shell metacharacters execute arbitrary commands. Version 2.1 of each definition fixes it. No in-the-wild exploitation or public PoC has been reported.

- **Published:** 2026-10-10T00:00:00Z
- **Last reviewed:** 2026-10-10T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-3226
- **ID:** TL-2026-3226
- **Severity:** CRITICAL (CVSS 9.6)
- **Category:** VULNERABILITY
- **Status:** ACTIVE
- **Detections:** 9 · **IOCs:** 12 (full data via the Threadlinqs MCP server — Purple tier)
- **CVEs:** CVE-2026-91140

## Description

Progress publishes AI agent and prompt definition files in the progress/datadirect-arc-ai-model-gen GitHub repository. They drive an AI-assisted workflow, run through VS Code Copilot Chat and GitHub Copilot CLI, that converts OpenAPI/Swagger specifications into DataDirect Autonomous REST Connector (.rest) configuration files. The affected definitions are ARCGenAI-Generator.agent.md v2.0, ARCGenAI-Generator.prompt.md v1.0 and ARCGenAI-EntityGen.agent.md v1.0.

Root cause (CWE-78): a filename value derived from an OpenAPI/Swagger document was used in a shell operation without sufficient validation and quoting. Per the NVD-derived description the vulnerable logic sits in the shell-based temporary-file cleanup instructions. An attacker who can get a crafted Swagger/OpenAPI document processed can embed shell metacharacters in the filename-derived value. The shell then interprets those characters as commands when a user invokes the generator, which gives arbitrary OS command execution in the context of the user running the agent.

Impact is scoped to developer workspaces and CI environments that process untrusted API specifications with the vulnerable definitions. These hosts typically hold source code and credentials. The published CVSS 3.1 vector (AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H, score 9.6) reflects user-triggered invocation of the generator. One secondary report states no user interaction is required, and the sources disagree on this point. The NVD/OpenCVE record lists UI:R.

Remediation requires no installer or patch. Defenders pull the updated v2.1 definitions from the vendor GitHub repository; the fix (commit 7ede6d96eb033d647ffdcabf8d8069c098293575) adds filename quoting and validation safeguards. Environments that previously processed untrusted specs with vulnerable versions should be inspected for evidence of command execution. As of 2026-10-10 the CVE is not in the CISA KEV catalog, no public PoC has been identified, no exploitation has been reported, and the reported EPSS 30-day probability is 1.9%. No threat actor attribution exists and no network IOCs have been published, so no BeaconBeagle correlation was applicable.

## MITRE ATT&CK

- T1195 Supply Chain Compromise
- T1203 Exploitation for Client Execution
- T1059.004 Command and Scripting Interpreter: Unix Shell
- T1204.002 User Execution: Malicious File
- T1552.001 Unsecured Credentials: Credentials In Files
- T1005 Data from Local System

## Sources

- [Critical Progress DataDirect GenAI Flaw Lets Attackers Execute Arbitrary OS Commands](https://gbhackers.com/critical-progress-datadirect-genai-flaw/)
- [OpenCVE - CVE-2026-91140](https://app.opencve.io/cve/CVE-2026-91140)
- [Progress DataDirect Critical Security Alert Bulletin - CVE-2026-91140](https://community.progress.com/s/article/Progress-DataDirect-Critical-Security-Alert-Bulletin-September-2026-CVE-2026-91140)
- [Fix commit in progress/datadirect-arc-ai-model-gen](https://github.com/progress/datadirect-arc-ai-model-gen/commit/7ede6d96eb033d647ffdcabf8d8069c098293575)
- [progress/datadirect-arc-ai-model-gen repository](https://github.com/progress/datadirect-arc-ai-model-gen)
- [Progress Patches Critical DataDirect ARCGenAI Command-Injection Flaw](https://letsdatascience.com/news/progress-fixes-critical-datadirect-agent-command-injection-9d92dcc7)
- [Progress DataDirect vulnerability CVE-2026-91140 (SecurityOnline)](https://securityonline.info/progress-datadirect-vulnerability-cve-2026-91140/)
- [Canadian Centre for Cyber Security - Progress security advisory AV26-1005](https://www.cyber.gc.ca/en/alerts-advisories/progress-security-advisory-av26-1005)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-3226
