Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
10.0

CVE-2026-80462: Chef Automate API gateway can grant unauthorized elevated access

CVE-2026-80462 · published 14 days ago
Summary

The API gateway and identity‑check routine in Chef Automate may let a person without a login obtain higher‑level permissions under certain circumstances. This could allow actions that should be restricted to trusted users, potentially affecting your automation workflows. Install the latest Chef Automate update and follow the vendor’s remediation steps, such as tightening network access to the API gateway.

What to do
  • Update progress software chef automate to version 4.13.520 or later.
Affected software
VendorProductAffected versions
progress software chef automate < 4.13.520
Original advisory text
A vulnerability in the Chef Automate API gateway and identity validation path may allow an unauthenticated actor to gain elevated access to protected Chef Automate functionality under specific cond...
A vulnerability in the Chef Automate API gateway and identity validation path may allow an unauthenticated actor to gain elevated access to protected Chef Automate functionality under specific conditions.
Severity
10.0 Critical
CVSS 3.1: 10.0 (MITRE)
Exploitation
EPSS <1%
Type
CWE-306Missing Authentication for Critical Function
Timeline
Published11 Sep 2026
Updated25 Sep 2026
First seen11 Sep 2026
Sources
CVE-2026-80462 · MITRE
Track software like this
Free during beta