Description
A vulnerability in the Chef Automate API gateway and identity validation path may allow an unauthenticated actor to gain elevated access to protected Chef Automate functionality under specific conditions.
Published: 2026-09-11
Score: 10 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Privilege Escalation
Action: Apply Patch
AI Analysis

Impact

This flaw, representing a CWE-306 authentication bypass, occurs in the Chef Automate API gateway and identity validation path, allowing an unauthenticated actor to gain elevated access to protected functionality under specific conditions. The vulnerability enables bypassing authentication controls, allowing the attacker to execute privileged operations that could compromise system integrity, confidentiality, and availability.

Affected Systems

Progress Software Chef Automate versions 4.13.516 through 4.13.519 are affected. Versions prior to 4.13.516 are not affected, and upgrades to 4.13.520 or later contain the fix.

Risk and Exploitability

The CVSS score of 10 signals critical vulnerability. No EPSS data is available, and the issue is not listed in CISA KEV, indicating no known active exploitation campaigns. The likely attack vector would be via the specific conditions required for the breach, which are not detailed in the description.

Generated by OpenCVE AI on September 11, 2026 at 14:53 UTC.

Remediation

Vendor Solution

Customers should upgrade to Chef Automate 4.13.520 or subsequent version. Versions prior to 4.13.516 are NOT affected.


Vendor Workaround

No approved workaround is currently available. Progress recommends upgrading to the fixed release when available.


OpenCVE Recommended Actions

  • Install the fix by upgrading to Chef Automate 4.13.520 or later.
  • Restrict network access to the API gateway so that only trusted hosts can reach it, reducing exposure to unauthenticated actors.
  • Implement continuous monitoring of audit logs for potential exploitation attempts.
  • Validate access that the API gateway strictly requires authentication before granting privileged operations.

Generated by OpenCVE AI on September 11, 2026 at 14:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 13 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Progress Software
Progress Software chef Automate
Vendors & Products Progress Software
Progress Software chef Automate

Fri, 11 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 11 Sep 2026 12:45:00 +0000

Type Values Removed Values Added
Description A vulnerability in the Chef Automate API gateway and identity validation path may allow an unauthenticated actor to gain elevated access to protected Chef Automate functionality under specific conditions.
Title Privilege Escalation in Progress Chef Automate
Weaknesses CWE-306
References
Metrics cvssV3_1

{'score': 10, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Progress Software Chef Automate
cve-icon MITRE

Status: PUBLISHED

Assigner: ProgressSoftware

Published:

Updated: 2026-09-18T12:04:29.296Z

Reserved: 2026-08-26T12:26:32.863Z

Link: CVE-2026-80462

cve-icon Vulnrichment

Updated: 2026-09-11T12:49:57.440Z

cve-icon NVD

Status : Deferred

Published: 2026-09-11T13:18:18.300

Modified: 2026-09-18T19:29:56.010

Link: CVE-2026-80462

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-13T19:56:23Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function