A vulnerability in the Chef Automate API gateway and identity validation path
Chef Automate can give an unauthenticated attacker elevated access to protected features. The attacker could access internal settings, identity controls, and managed infrastructure.
- Severity
- CriticalCVSS 3.1 · 10.0 · progress.com
- Fix
- Fixed in 4.13.520
- Affected versions
- 4.13.516 to before 4.13.520
- Weakness
- CWE-306Missing Authentication for Critical Function
- Affects
- Chef Automate
- Exploited
- Not confirmedNo confirmation recorded
- CISA SSVC
- No known exploitationAutomatable: yes · Technical impact: total
- EU ID
- EUVD-2026-76099ENISA vulnerability database
How it works
- An attacker sends a network request to Chef Automate without signing in.
- Under specific conditions, its request gateway and identity checks allow protected access without authentication.
- The public record does not explain those triggering conditions.
- Successful access can expose internal settings and permit actions across managed infrastructure.
What to do
If you administer Chef Automate on Linux x86, compare its installed version with the advisory. Treat versions 4.13.516 through 4.13.519 as affected. Treat versions older than 4.13.516 as unaffected by this specific flaw.
Update Chef Automate to version 4.13.520 or later. Confirm the installed version is at least 4.13.520 after upgrading.
Technical details
CVE-2026-80462 affects Chef Automate 4.13.516 through 4.13.519. Missing authentication in the API gateway and identity validation path can give a remote, unauthenticated attacker elevated access. Successful exploitation may expose configuration data, identity and access-management operations, protected APIs, or actions across managed infrastructure. Progress identifies 4.13.520 as the fixed release and provides no approved workaround.
Severity breakdown
- Attack vector Network Requires network access to the vulnerable service
- Attack complexity Low Low complexity under the assessed conditions
- Privileges required None Attacker needs no account or login
- User interaction None No victim action needed
- Scope Changed Impact crosses a security authority boundary
- Confidentiality impact High Sensitive data can be exposed with serious impact
- Integrity impact High Protected data can be changed with serious impact
- Availability impact High The service can stop or suffer serious disruption
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H Open in FIRST.org calculatorReferences
- rapid7.com · CVE-2026-80462 third party advisory technical description
- cve.org · CVERecord vdb entry
- radar.offseq.com · cve-2026-80462-cwe-306-missing-authentication-for-critical-function-in-progress-software-chef-automate-cfce7409b20e5b5f third party advisory
- tenable.com · CVE-2026-80462 third party advisory vdb entry
- cvefeed.io · CVE-2026-80462 third party advisory vdb entry
- euvd.enisa.europa.eu · EUVD-2026-76099 vdb entry
- cveawg.mitre.org · CVE-2026-80462
- community.progress.com · Critical-Security-Bulletin---August-2026---Chef-Automate-Security-Vulnerability vendor-advisory NVD