CVE-2026-80462 PUBLISHED

Privilege Escalation in Progress Chef Automate

Assigner: ProgressSoftware
Reserved: 26.08.2026 Published: 11.09.2026 Updated: 11.09.2026

A vulnerability in the Chef Automate API gateway and identity validation path may allow an unauthenticated actor to gain elevated access to protected Chef Automate functionality under specific conditions.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
CVSS Score: 10

Product Status

Vendor Progress Software
Product Chef Automate
Versions Default: unaffected
  • affected from 4.13.516 to 4.13.520 (excl.)
  • unaffected from 1.0.0 to 4.13.516 (excl.)

Workarounds

No approved workaround is currently available. Progress recommends upgrading to the fixed release when available.

Solutions

Customers should upgrade to Chef Automate 4.13.520 or subsequent version. Versions prior to 4.13.516 are NOT affected.

References

Problem Types

  • CWE-306 Missing authentication for critical function CWE

Impacts

  • Successful exploitation may result in unauthorized access to internal Chef Automate configuration data, identity and access-management operations, protected APIs, or actions across managed infrastructure.