---
id: CVE-2026-80462
title: >-
  A vulnerability in the Chef Automate API gateway and identity validation path
  may allow an unauthenticated actor to gain elevated access to protected Chef
  Automate functionality under specific conditions.
summary: >-
  A vulnerability in the Chef Automate API gateway and identity validation path
  may allow an unauthenticated actor to gain elevated access to protected Chef
  Automate functionality under specific conditions.
severity: critical
cvss: 10
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H'
cwe:
  - CWE-306
vendor: Progress Software
product: Chef Automate
affected:
  - chef_automate >= 4.13.516 < 4.13.520
published: '2026-09-11'
updated: '2026-09-18'
sourceUpdated: '2026-09-18T19:29:56.010'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-80462'
references:
  - url: >-
      https://community.progress.com/s/article/Critical-Security-Bulletin---August-2026---Chef-Automate-Security-Vulnerability
    label: security@progress.com
tags:
  - nvd
  - cve.org
epss: 0.00483
epssPercentile: 0.38937
ssvc:
  exploitation: none
  automatable: 'yes'
  technicalImpact: total
  timestamp: '2026-09-11T12:49:17.205349Z'
ingestedAt: '2026-09-11T16:45:47.911Z'
---

## Overview

A vulnerability in the Chef Automate API gateway and identity validation path may allow an unauthenticated actor to gain elevated access to protected Chef Automate functionality under specific conditions.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
