Unauthenticated Access Vulnerability in Chef 360 by Chef Software
CVE-2026-8668

2.3LOW

Key Information:

Status
Vendor
CVE Published:
18 June 2026

What is CVE-2026-8668?

A static credential embedded in Chef 360 versions prior to v1.7.0 allowed unauthorized users to gain access to internal message queues, which contained tenant-specific identifiers. This vulnerability posed significant risks to data privacy and security by enabling potential leakage of sensitive tenant information. The issue has been addressed by rotating the static credential and implementing per-tenant access controls in subsequent releases, effectively eliminating this security risk.

Affected Version(s)

Chef360 64 bit 0 < 1.7.1

References

CVSS V4

Score:
2.3
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.