Unauthenticated Access Vulnerability in Chef Automate API Gateway
CVE-2026-80462

10CRITICAL

Key Information:

Vendor
CVE Published:
11 September 2026

What is CVE-2026-80462?

A security flaw has been identified in the Chef Automate API gateway that could enable an attacker without proper credentials to gain unauthorized elevated access to sensitive functionalities. This vulnerability arises under certain conditions, specifically concerning the identity validation path, making it critical for users to apply security updates to protect their systems and prevent unauthorized exploitation.

Affected Version(s)

Chef Automate Linux 4.13.516 < 4.13.520

Chef Automate Linux 1.0.0 < 4.13.516

References

CVSS V3.1

Score:
10
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.