Vulnerability Intelligence Report
Privilege Escalation in Progress Chef Automate
CVE-2026-80462
A vulnerability in the Chef Automate API gateway and identity validation path may allow an unauthenticated actor to gain elevated access to protected Chef Automate functionality under specific conditions.
No Active Exploit Signals
CVSS Base Score
10.0
CRITICAL
Exploitability:3.9
Impact Score:6.1
EPSS Probability:0.30%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Weaknesses (CWE)
CWE-306 ↗CWE-306 Missing authentication for critical function
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| Progress Software | Chef Automate | 4.13.516 < 4.13.520 (affected), 1.0.0 < 4.13.516 (unaffected) |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
EPSS Score
0.305%
GitHub Advisory
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | Progress Software Corporation · Vendor · USA |
| Reserved | 2026-08-26T12:26:32 |
| Published | 2026-09-11T12:28:49 |
| Last Updated | 2026-09-18T12:04:29 |
Community Chatter & Buzz