• PATCH AVAILABLE

CVE-2026-80462: pre-auth privilege escalation in Progress Software Chef Automate

An unauthenticated attacker can gain elevated access to protected Chef Automate functionality by abusing the API gateway and identity validation path, allowing full control of impacted instances. CVE-2026-80462 affects Chef Automate 4.x releases from 4.13.516 up to but not including 4.13.520; the issue is fixed in 4.13.520. The vulnerability requires only network access to the affected service and no valid account or user interaction, and it can lead to complete confidentiality, integrity, and availability loss on vulnerable servers.

Published Updated Source: CVE Program, NVD, FIRST EPSS, Vendor advisory

CVSS 3.1
10CRITICAL
EPSS
0.00483
CWE
CWE-306
KEV DUE DATE
Not listed
PATCH
Available

DIRAS TAKE

Treat this as high urgency: an unauthenticated access flaw grants elevated access and Progress published a fixed release (4.13.520). Prioritize upgrading internet-facing or broadly reachable Chef Automate instances to 4.13.520 immediately.

What is CVE-2026-80462?

An unauthenticated attacker can gain elevated access to protected Chef Automate functionality by abusing the API gateway and identity validation path, allowing full control of impacted instances. CVE-2026-80462 affects Chef Automate 4.x releases from 4.13.516 up to but not including 4.13.520; the issue is fixed in 4.13.520. The vulnerability requires only network access to the affected service and no valid account or user interaction, and it can lead to complete confidentiality, integrity, and availability loss on vulnerable servers. The weakness is classified as CWE-306 (Missing Authentication for Critical Function).

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Which versions of Progress Software Chef Automate are affected?

BRANCHAFFECTEDFIXED
4.x4.13.516 – before 4.13.5204.13.520

Is CVE-2026-80462 being exploited?

There are no public reports of exploitation as of 2026-09-30.

How to fix CVE-2026-80462

  1. Upgrade Chef Automate 4.x instances to 4.13.520.
  2. If you cannot upgrade immediately, restrict network access to the Chef Automate API (firewall, allowlist) to trusted hosts only.
  3. Apply vendor-recommended mitigations and configuration changes from Progress, and review their advisory for any additional steps.
  4. Monitor Chef Automate logs and alerts for unusual authentication or privilege changes and prepare to investigate suspicious activity.

Frequently asked questions

Is CVE-2026-80462 being actively exploited?

There are no public reports of active exploitation of CVE-2026-80462 as of 2026-09-30.

Which Chef Automate versions are affected by CVE-2026-80462?

Chef Automate 4.x releases from 4.13.516 through versions before 4.13.520 are affected; the issue is fixed in 4.13.520.

Is there a patch for CVE-2026-80462?

Yes. Progress fixed the vulnerability in Chef Automate version 4.13.520; upgrade to that release.

Does CVE-2026-80462 require authentication?

No. The vulnerability can be exploited by an unauthenticated actor with network access to the Chef Automate API gateway.

References