CVE-2026-80462

Summary

A vulnerability in the Chef Automate API gateway and identity validation path may allow an unauthenticated actor to gain elevated access to protected Chef Automate functionality under specific conditions.

Affected Software

VendorProductVersion RangeStatus
Progress SoftwareChef Automate4.13.516 < 4.13.520affected
Progress SoftwareChef Automate1.0.0 < 4.13.516unaffected

Weaknesses

  • CWE-306: CWE-306 Missing authentication for critical function

Workarounds

No approved workaround is currently available. Progress recommends upgrading to the fixed release when available.

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: yes
    • Technical Impact: total

References