A vulnerability in the Chef Automate API gateway and identity validation path may allow an unauthenticated actor to gain elevated access to protected Chef Automate functionality under specific conditions.
Metrics
Affected Vendors & Products
References
History
Fri, 11 Sep 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 11 Sep 2026 12:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability in the Chef Automate API gateway and identity validation path may allow an unauthenticated actor to gain elevated access to protected Chef Automate functionality under specific conditions. | |
| Title | Privilege Escalation in Progress Chef Automate | |
| Weaknesses | CWE-306 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: ProgressSoftware
Published: 2026-09-11T12:28:49.216Z
Updated: 2026-09-11T12:50:02.154Z
Reserved: 2026-08-26T12:26:32.863Z
Link: CVE-2026-80462
Updated: 2026-09-11T12:49:57.440Z
Status : Received
Published: 2026-09-11T13:18:18.300
Modified: 2026-09-11T13:18:18.300
Link: CVE-2026-80462
No data.