CVE-2026-80462: Progress Software Chef Automate
Critical severity, CVSS 10.0. EPSS: 0.5% chance of exploitation in the next 30 days.
A vulnerability in the Chef Automate API gateway and identity validation path may allow an unauthenticated actor to gain elevated access to protected Chef Automate functionality under specific conditions.
Affected products
- Progress Software Chef Automate: from 4.13.516, before 4.13.520 (fixed in 4.13.520)
Published 2026-09-11. Last modified 2026-09-18.