Unauthenticated Access Vulnerability in Chef 360 by Chef Software
CVE-2026-8668
2.3LOW
What is CVE-2026-8668?
A static credential embedded in Chef 360 versions prior to v1.7.0 allowed unauthorized users to gain access to internal message queues, which contained tenant-specific identifiers. This vulnerability posed significant risks to data privacy and security by enabling potential leakage of sensitive tenant information. The issue has been addressed by rotating the static credential and implementing per-tenant access controls in subsequent releases, effectively eliminating this security risk.
Affected Version(s)
Chef360 64 bit 0 < 1.7.1
