Junglewise Threat Intelligence

CVE-2026-80462: Progress Chef Automate API gateway authentication bypass

CVE-2026-80462 · Severity: critical · CVSS 10 · Published 2026-09-11

Vendors: Progress.

Executive brief

Chef Automate is a configuration management and infrastructure automation platform used by enterprises to manage servers and applications at scale. A vulnerability in its API gateway's identity validation allows unauthenticated attackers to bypass authentication and gain full administrative access to the system, potentially enabling complete compromise of managed infrastructure.

Technical details

This is an authentication bypass vulnerability in the Chef Automate API gateway's identity validation logic. The flaw allows an unauthenticated actor to craft requests that bypass the authentication pathway and gain elevated privileges to protected API functionality. The vulnerability is network-reachable and requires no prior authentication or special privileges to exploit, though it may require specific conditions to be met. Successful exploitation grants attackers complete administrative access to Chef Automate, enabling them to modify configurations, execute arbitrary code on managed nodes, and compromise the entire infrastructure under management. A patch is expected to be available from Progress.

Affected products

  • Progress Chef Automate <UNKNOWN>

Timeline

  • 2026-09-11: disclosed
  • 2026-08: advisory: Progress issued a critical security bulletin in August 2026

References