Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
10.0
CVE-2026-80462: Chef Automate API gateway can grant unauthorized elevated access
CVE-2026-80462 · published 14 days ago
Summary
The API gateway and identity‑check routine in Chef Automate may let a person without a login obtain higher‑level permissions under certain circumstances. This could allow actions that should be restricted to trusted users, potentially affecting your automation workflows. Install the latest Chef Automate update and follow the vendor’s remediation steps, such as tightening network access to the API gateway.
What to do
- Update progress software chef automate to version 4.13.520 or later.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| progress software | chef automate | < 4.13.520 |
Original advisory text
A vulnerability in the Chef Automate API gateway and identity validation path may allow an unauthenticated actor to gain elevated access to protected Chef Automate functionality under specific cond...
A vulnerability in the Chef Automate API gateway and identity validation path may allow an unauthenticated actor to gain elevated access to protected Chef Automate functionality under specific conditions.
Severity
10.0
Critical
CVSS 3.1: 10.0 (MITRE)
Exploitation
EPSS <1%
Type
CWE-306Missing Authentication for Critical Function
Timeline
Published11 Sep 2026
Updated25 Sep 2026
First seen11 Sep 2026
Track software like this
Free during beta