A vulnerability in the Chef Automate API gateway and identity validation path

Published September 11, 2026 CVE-2026-80462

Chef Automate can give an unauthenticated attacker elevated access to protected features. The attacker could access internal settings, identity controls, and managed infrastructure.

Severity
CriticalCVSS 3.1 · 10.0 · progress.com
Fix
Fixed in 4.13.520
Affected versions
4.13.516 to before 4.13.520
Weakness
CWE-306Missing Authentication for Critical Function
Affects
Chef Automate
Exploited
Not confirmedNo confirmation recorded
CISA SSVC
No known exploitationAutomatable: yes · Technical impact: total
EU ID
EUVD-2026-76099ENISA vulnerability database

How it works

  • An attacker sends a network request to Chef Automate without signing in.
  • Under specific conditions, its request gateway and identity checks allow protected access without authentication.
  • The public record does not explain those triggering conditions.
  • Successful access can expose internal settings and permit actions across managed infrastructure.

What to do

If you administer Chef Automate on Linux x86, compare its installed version with the advisory. Treat versions 4.13.516 through 4.13.519 as affected. Treat versions older than 4.13.516 as unaffected by this specific flaw.

Update Chef Automate to version 4.13.520 or later. Confirm the installed version is at least 4.13.520 after upgrading.

Technical details

CVE-2026-80462 affects Chef Automate 4.13.516 through 4.13.519. Missing authentication in the API gateway and identity validation path can give a remote, unauthenticated attacker elevated access. Successful exploitation may expose configuration data, identity and access-management operations, protected APIs, or actions across managed infrastructure. Progress identifies 4.13.520 as the fixed release and provides no approved workaround.

Severity breakdown

  • Attack vector Network Requires network access to the vulnerable service
  • Attack complexity Low Low complexity under the assessed conditions
  • Privileges required None Attacker needs no account or login
  • User interaction None No victim action needed
  • Scope Changed Impact crosses a security authority boundary
  • Confidentiality impact High Sensitive data can be exposed with serious impact
  • Integrity impact High Protected data can be changed with serious impact
  • Availability impact High The service can stop or suffer serious disruption
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H Open in FIRST.org calculator