securityonline.info 12 Sept 2026, 01:41 UTC

Critical Chef Automate Flaw Lets Attackers Seize Infrastructure Control

Critical Chef Automate Flaw Lets Attackers Seize Infrastructure Control
CyberSIXT Evidence Panel
CISA KEV Not in KEV
Patch Patch Status Unknown

PROGRESS Software has published a critical advisory for Chef Automate, warning of CVE-2026-80462 with a CVSS v3 score of 10.0. The flaw permits unauthenticated attackers to gain elevated administrative privileges by bypassing identity checks through the application gateway and inter-service token verification pathways.

In practical terms, a remote actor could send crafted requests to private endpoints and obtain privileged access to protected Chef Automate functionality, potentially allowing full control over configured infrastructure. The vendor notes that there is no public PoC and that researchers have not observed active exploitation in the wild to date.

Affected products are Chef Automate on on‑premises deployments running version 4.13.516. The issue does not affect Chef 360 or Chef Infra Server. Progress has released fixes in Chef Automate 4.13.520 for on‑premises installations, and patches have already been applied to all Chef Automate SaaS environments.

Administrators are urged to upgrade immediately to 4.13.520 (and to 1.0.0 as indicated by the advisory) to mitigate the vulnerability and prevent potential compromise of exposed configuration data and automatic policy changes across managed fleets. The advisory emphasises upgrading promptly given the critical severity and the potential impact on DevOps workflows and cloud deployments. No evidence of exploitation is currently confirmed, but rapid remediation is recommended.

View full article

Article by CyberSIXT