Progress security advisory (AV26-915)
Chef Automate, a tool for managing software on servers, has a flaw that lets attackers crash your server or run malicious code. Progress Software just warned admins to update to version 4.13.520 or higher.
- Severity
- Not scoredNo CVSS score recorded
- Fix
- Fixed in 4.13.520
- Exploited
- Not confirmedNo confirmation recorded
How it works
- An attacker sends a specially crafted request to Chef Automate's management API.
- The tool does not properly check the size of the incoming data, so it crashes or lets the attacker run commands on your server.
What to do
If you run Chef Automate on any server, check your installed version by opening the About or version screen. If it is 4.13.520 or earlier, you are affected.
Update Chef Automate to version 4.13.520 or later. Check Progress Software's advisory for the latest instructions: Progress Security Advisory AV26-915.
Technical details
Serial Number: AV26-915 Date: September 11, 2026 As of September 11, 2026, Progress Software is affected by a vulnerability in the following product: Chef Automate Prior to 4.13.520 The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.