Junglewise Threat Intelligence

CVE-2026-8668: Progress Chef 360 static credential in internal message queues

CVE-2026-8668 · Severity: info · CVSS 2.3 · Published 2026-06-18

Vendors: Progress Software.

Executive brief

Progress Chef 360, a platform used for automating IT infrastructure and security compliance, contained a hardcoded credential in its internal messaging system. This flaw could allow an unauthorized person to access internal message queues, which contain sensitive identifiers for different customer accounts (tenants). While the risk is limited to viewing certain internal data, it could potentially lead to further unauthorized access or information gathering in multi-tenant environments.

Technical details

A vulnerability in Progress Chef 360 (specifically the Delivery service queue module) stems from the use of a static, hardcoded credential. This flaw allows an unauthenticated attacker with network access to the internal message queue to intercept or read messages. These messages contain tenant-specific identifiers, which could be leveraged for further reconnaissance or cross-tenant data exposure. The issue is addressed in version 1.7.1 by rotating the static credential and implementing per-tenant access controls, effectively deprecating the vulnerable access method.

Affected products

  • Progress Software Chef 360 Platform 0 to 1.7.0

Timeline

  • 2026-05-12: patched: Version 1.7.1 released to address security hardening.
  • 2026-06-18: disclosed: CVE-2026-8668 published.

References