A vulnerability in the Chef Automate API gateway and identity validation path may allow an unauthenticated actor to gain elevated access to protected Chef Automate functionality under specific conditions.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
Customers should upgrade to Chef Automate 4.13.520 or subsequent version. Versions prior to 4.13.516 are NOT affected.
Workaround
No approved workaround is currently available. Progress recommends upgrading to the fixed release when available.
References
History
Fri, 11 Sep 2026 12:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability in the Chef Automate API gateway and identity validation path may allow an unauthenticated actor to gain elevated access to protected Chef Automate functionality under specific conditions. | |
| Title | Privilege Escalation in Progress Chef Automate | |
| Weaknesses | CWE-306 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: ProgressSoftware
Published:
Updated: 2026-09-11T12:50:02.154Z
Reserved: 2026-08-26T12:26:32.863Z
Link: CVE-2026-80462
No data.
No data.
No data.
OpenCVE Enrichment
No data.
Weaknesses