CVE-2026-80462
10.0Progress Software · Chef Automate
A critical flaw in the Chef Automate API gateway allows unauthenticated attackers to bypass identity validation and gain elevated access to protected system functions.
Executive summary
Progress Software Chef Automate is vulnerable to an unauthenticated access bypass flaw that could allow a remote attacker to gain full control over the application.
Vulnerability
This is a missing authentication for critical function vulnerability (CWE-306) located within the API gateway and identity validation path, which permits unauthenticated actors to interact with restricted functionality.
Business impact
The vulnerability carries a CVSS score of 10.0, indicating a critical risk that warrants immediate attention. Successful exploitation allows an unauthorized party to achieve total system compromise, potentially leading to the theft of sensitive configuration data, unauthorized modification of infrastructure settings, and complete service disruption.
Remediation
Immediate Action: Administrators must upgrade to Chef Automate version 4.13.520 or newer as soon as possible to patch the vulnerable API gateway.
Proactive Monitoring: Review API access logs for anomalous requests, specifically targeting non-standard endpoints or spikes in traffic originating from unexpected IP addresses.
Compensating Controls: Deploy or update Web Application Firewall rules to restrict access to the Chef Automate API to known, trusted management segments until the patching process is complete.
Exploitation status
Public Exploit Available: No
Analyst recommendation
Due to the critical nature of this vulnerability and the potential for full system compromise, this issue must be prioritized for immediate remediation. Organizations should verify their current version of Chef Automate and apply the 4.13.520 update across all affected environments without delay.
More Progress Software CVEs all →
History
- Disclosed CVE record published
- Collected by CVE Brief via github
- Analyst report written
- Published in the daily brief critical section