Progress Software published a critical security bulletin, disclosing a maximum-severity flaw. The newly identified Chef Automate vulnerability allows unauthenticated attackers to gain elevated privileges. Consequently, administrators must update their environments immediately to prevent unauthorized infrastructure control.
TL;DR
A critical flaw in Chef Automate permits unauthenticated remote actors to gain administrative access. The vulnerability enables attackers to bypass identity checks and execute commands across managed systems. Organizations must upgrade on-premises deployments immediately to protect their DevOps infrastructure.
- CVE: CVE-2026-80462
- CVSS: 10.0 (Critical · CVSSv3)
- Product: Progress Software Chef Automate
- Affected: 4.13.516
- Impact: Privilege Escalation in Progress Chef Automate
- Status: No confirmed exploitation yet
- Patched in: 4.13.520, 1.0.0
- Action: Update to 4.13.520, 1.0.0 now
Track every Progress CVE the moment it's exploited.
Get free email alertsWhy This Threat Matters
Industry estimates show that thousands of enterprise teams rely on Chef Automate to configure global server fleets. Therefore, flaws in this management plane create severe operational risks. If attackers compromise this platform, they can access sensitive system configurations. Furthermore, threat actors can abuse identity management tools to push malicious changes across entire corporate clouds.
How the Attack Works
The security defect exists within the application gateway and identity verification pathways. According to the vendor advisory, “Under specific conditions, an unauthenticated actor may be able to gain elevated access to protected Chef Automate functionality.”
Specifically, the gateway improperly verifies trust tokens between internal microservices. This flaw allows a remote attacker to send crafted requests directly to private endpoints. As a result, the intruder gains elevated access without supplying valid credentials. Progress confirmed that researchers have observed no active in-the-wild exploitation. In addition, no public proof-of-concept exploit code exists.
Affected Versions
This critical Chef Automate vulnerability impacts on-premises and SaaS deployments running version 4.13.516. However, the issue does not affect Chef 360 or Chef Infra Server products.
Patch and Mitigation Steps
Administrators must upgrade on-premises installations to version 4.13.520 immediately. The advisory states, “Progress has addressed this vulnerability and strongly recommends upgrading to the fixed release, Chef Automate 4.13.520.” Meanwhile, the vendor has already applied patches to all Chef Automate SaaS environments.
Support Our Threat Intelligence
Find our vulnerability reports and weekly recaps helpful? Support our work today and unlock a 100% ad-free reading experience!