Progress security advisory (AV26-915)

Published September 11, 2026

Chef Automate, a tool for managing software on servers, has a flaw that lets attackers crash your server or run malicious code. Progress Software just warned admins to update to version 4.13.520 or higher.

Severity
Not scoredNo CVSS score recorded
Fix
Fixed in 4.13.520
Exploited
Not confirmedNo confirmation recorded

How it works

  • An attacker sends a specially crafted request to Chef Automate's management API.
  • The tool does not properly check the size of the incoming data, so it crashes or lets the attacker run commands on your server.

What to do

If you run Chef Automate on any server, check your installed version by opening the About or version screen. If it is 4.13.520 or earlier, you are affected.

Update Chef Automate to version 4.13.520 or later. Check Progress Software's advisory for the latest instructions: Progress Security Advisory AV26-915.

Technical details

Serial Number: AV26-915 Date: September 11, 2026 As of September 11, 2026, Progress Software is affected by a vulnerability in the following product: Chef Automate Prior to 4.13.520 The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.