ZeroHour

CVE-2026-80462

moderate

Unauthenticated Privilege Bypass in Progress Chef Automate API Gateway

CVSS 3.1
10.0 critical
EPSS
Published
()
Modified
AI analysis

Progress (Chef) has disclosed a critical authentication flaw, classified as CWE-306 (missing authentication for critical function), in the Chef Automate API gateway and its identity validation path. Under specific conditions, an unauthenticated remote actor can send requests that bypass identity validation and gain elevated access to protected Chef Automate functionality; the scope-changed CVSS 3.1 score of 10.0 (AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H) indicates impact can extend beyond the gateway itself, with high confidentiality, integrity, and availability impact. Any organization running Chef Automate is affected, with the greatest risk for deployments whose API gateway is reachable from untrusted or internet-facing networks, though the vendor notes exploitation requires specific conditions. There is no public proof-of-concept, the flaw is not in CISA's Known Exploited Vulnerabilities catalog, and no exploitation is currently known.

What to do: Upgrade Chef Automate to the fixed release specified in the Progress/Chef security advisory as soon as it is published (exact affected/fixed versions are not listed in the available data). Until patched, restrict access to the Automate API gateway to trusted networks or VPN, verify it is not exposed to the internet, and review logs for unauthenticated requests against protected API endpoints. Given the CVSS 10.0 rating, prioritize patching any deployment with an externally reachable gateway.

Affected
Progress (Chef) Chef Automate
Estimated exposure
moderate≈1k–10k enterprise deployments (order of 10k–100k users), of which likely only a subset have the API gateway network-exposed — estimate — Chef Automate is an enterprise, typically on-premises control plane usually deployed as one or a few instances per organization, so Progress/Chef's long-standing enterprise customer base suggests on the order of thousands of installations;…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A vulnerability in the Chef Automate API gateway and identity validation path may allow an unauthenticated actor to gain elevated access to protected Chef Automate functionality under specific conditions.

Weakness
CWE-306
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.