Description
A vulnerability in the Chef Automate API gateway and identity validation path may allow an unauthenticated actor to gain elevated access to protected Chef Automate functionality under specific conditions.
Published: 2026-09-11
Score: 10 Critical
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

Vendor Solution

Customers should upgrade to Chef Automate 4.13.520 or subsequent version. Versions prior to 4.13.516 are NOT affected.


Vendor Workaround

No approved workaround is currently available. Progress recommends upgrading to the fixed release when available.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 11 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 11 Sep 2026 12:45:00 +0000

Type Values Removed Values Added
Description A vulnerability in the Chef Automate API gateway and identity validation path may allow an unauthenticated actor to gain elevated access to protected Chef Automate functionality under specific conditions.
Title Privilege Escalation in Progress Chef Automate
Weaknesses CWE-306
References
Metrics cvssV3_1

{'score': 10, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: ProgressSoftware

Published:

Updated: 2026-09-11T12:50:02.154Z

Reserved: 2026-08-26T12:26:32.863Z

Link: CVE-2026-80462

cve-icon Vulnrichment

Updated: 2026-09-11T12:49:57.440Z

cve-icon NVD

Status : Received

Published: 2026-09-11T13:18:18.300

Modified: 2026-09-11T13:18:18.300

Link: CVE-2026-80462

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function