Executive brief
Chef Automate is a configuration management and infrastructure automation platform used by enterprises to manage servers and applications at scale. A vulnerability in its API gateway's identity validation allows unauthenticated attackers to bypass authentication and gain full administrative access to the system, potentially enabling complete compromise of managed infrastructure.
Technical details
This is an authentication bypass vulnerability in the Chef Automate API gateway's identity validation logic. The flaw allows an unauthenticated actor to craft requests that bypass the authentication pathway and gain elevated privileges to protected API functionality. The vulnerability is network-reachable and requires no prior authentication or special privileges to exploit, though it may require specific conditions to be met. Successful exploitation grants attackers complete administrative access to Chef Automate, enabling them to modify configurations, execute arbitrary code on managed nodes, and compromise the entire infrastructure under management. A patch is expected to be available from Progress.
Affected products
- Progress Chef Automate <UNKNOWN>
Timeline
- 2026-09-11: disclosed
- 2026-08: advisory: Progress issued a critical security bulletin in August 2026