CVE-2026-80462: Privilege Escalation in Progress Chef Automate
A vulnerability in the Chef Automate API gateway and identity validation path may allow an unauthenticated actor to gain elevated access to protected Chef Automate functionality under specific conditions.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 4.13.520
Event History
Frequently Asked Questions
Does exploitation require an existing Chef Automate account or user interaction?
No. The CVSS vector indicates no privileges and no user interaction are required, and the issue may be exploitable by an unauthenticated actor under specific conditions.
Which Chef Automate components should be considered in scope?
The affected functionality is identified as the Chef Automate API gateway and the identity validation path. The provided information does not identify affected versions or configurations.
What is the potential security impact if the issue is exploited?
Successful exploitation may provide elevated access to protected Chef Automate functionality. The CVSS vector rates confidentiality, integrity, and availability impact as high, with scope changed.