Full Report
Progress security advisory (AV26-1005)
Analysis Summary
# Vulnerability: Path Traversal in Progress Autonomous REST Connector GenAI Agents
## CVE Details
- **CVE ID:** CVE-2026-91140
- **CVSS Score:** 9.8 (Critical)
- **CWE:** CWE-22 (Improper Limitation of a Pathname to a Restricted Directory / Path Traversal)
## Affected Systems
- **Products:** Progress Software Autonomous REST Connector (ARC) GenAI Agents ARCGenAI-Generator
- **Versions:** All versions prior to 2.1
- **Configurations:** Systems utilizing the GenAI-Generator component for processing REST requests.
## Vulnerability Description
A critical path traversal vulnerability exists in the Progress ARCGenAI-Generator component. The flaw allows an unauthenticated attacker to manipulate file paths in requests to the application. Due to insufficient input validation, an attacker can escape the intended directory structure to read, modify, or delete sensitive files on the host file system. Given the nature of GenAI agents, this could also lead to the injection of malicious prompts or the exfiltration of training data and configuration secrets.
## Exploitation
- **Status:** Not currently reported as exploited in the wild; however, the technical details suggest high exploitability.
- **Complexity:** Low
- **Attack Vector:** Network (Remote)
## Impact
- **Confidentiality:** High (Full access to system files and GenAI configuration)
- **Integrity:** High (Ability to modify application files or agent logic)
- **Availability:** High (Potential for system disruption or file deletion)
## Remediation
### Patches
- **Progress Autonomous REST Connector GenAI Agents:** Upgrade to version **2.1** or later immediately.
### Workarounds
- There are no official functional workarounds that maintain full feature parity. Progress strongly recommends a full version upgrade.
- As a temporary measure, restrict network access to the ARCGenAI-Generator endpoint to trusted internal IPs only.
## Detection
- **Indicators of Compromise:** Look for unexpected directory traversal patterns (e.g., `../`, `..\`, `%2e%2e%2f`) in HTTP request logs targeting the ARCGenAI-Generator service.
- **Detection methods and tools:**
- Deploy Web Application Firewall (WAF) rules specifically designed to block path traversal sequences.
- Monitor file integrity on the host for unauthorized changes to configuration files.
## References
- [Progress DataDirect Critical Security Alert Bulletin– September 2026](https[:]//community[.]progress[.]com/s/article/Progress-DataDirect-Critical-Security-Alert-Bulletin-September-2026-CVE-2026-91140)
- [Progress Trust Center](https[:]//trust[.]progress[.]com/)
- [Canadian Centre for Cyber Security Advisory AV26-1005](https[:]//www[.]cyber[.]gc[.]ca/en/alerts-advisories/progress-security-advisory-av26-1005)