Skip to content
Progress SoftwareCVE-2026-80462

Progress Software Chef Automate: missing authentication

Critical10.0CVE-2026-80462 · Published Sep 11, 2026 · updated Sep 18, 2026

A vulnerability in the Chef Automate API gateway and identity validation path may allow an unauthenticated actor to gain elevated access to protected Chef Automate functionality under specific conditions.

Progress Software advisory

Affected versions

PackageAffectedFixed in
Chef Automate
Product
>= 4.13.516, < 4.13.5204.13.520
Details and references

More Progress Software advisories

All Progress Software

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.