CVE-2026-80462
A flaw in Chef Automate’s API gateway lets an unauthenticated user gain elevated access to protected functions under certain conditions. The issue can lead to full control over the system. It is critical because no authentication is required.
No official fix yet. If none appears within 45 days of first tracking, this entry is removed automatically.
Who is affected
Chef Automate (any version, as no specific versions are listed).
Real-world impact
An attacker who can reach the API gateway could elevate privileges and access or modify protected resources, potentially taking full control of the Chef Automate environment.
Why this severity
The CVSS score of 10 reflects that the vulnerability requires no authentication, has no user interaction, and gives complete compromise of confidentiality, integrity, and availability.
What to do about it
No official fix or mitigation is documented in the sources yet. Monitor the vendor advisory and apply the patch as soon as it is released.
No fix documented in sources