Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4876 articles · 221243 vulns · 37/41 feeds (7d)
← Back to list
10.0
CVE-2026-80462PATCHED
progress · chef automate

Privilege Escalation in Progress Chef Automate

Description

A vulnerability in the Chef Automate API gateway and identity validation path may allow an unauthenticated actor to gain elevated access to protected Chef Automate functionality under specific conditions.

Affected Products

VendorProductVersions
progresschef automate4.13.516

References

  • https://community.progress.com/s/article/Critical-Security-Bulletin---August-2026---Chef-Automate-Security-Vulnerability(vendor-advisory)

Related News (1 articles)

Tier C
VulDB11d ago
CVE-2026-80462 | Progress Chef Automate up to 4.13.515/4.13.519 API Gateway privileges management
→ No new info (linked only)

Discussion (0)

Loading…

CVSS 3.110.0 CRITICAL
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
CISA KEV❌ No
Actively exploited❌ No
Patch available
4.13.5201.0.0
CWECWE-306
PublishedSep 11, 2026
Trending Score12
Source articles1
Independent1
Info Completeness0/14
Missing: cve_id, title, description, vendor, product, versions, cvss, epss, cwe, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

HIGHCVE-2026-13184
RadAsyncUpload Default HMAC Key Fallback Vulnerability in Telerik UI for ASP.NET AJAX
Trending: 9
HIGHCVE-2026-13183
RadAsyncUpload Upload Metadata Timing Oracle Vulnerability in Telerik UI for ASP.NET AJAX
Trending: 9
HIGHCVE-2026-19219
DialogHandler UploadPaths Tampering Vulnerability in Telerik UI for ASP.NET AJAX
Trending: 5
HIGHCVE-2026-18672
RadImageEditor ClientState Unauthenticated Arbitrary File Read Vulnerability in Telerik UI for ASP.NET AJAX
Trending: 5
HIGHCVE-2026-16139
Arbitrary file write via path traversal in Progress ShareFile Storage Zones Controller potentially leading to remote code execution
Trending: 1

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Sep 11, 2026
Discovered by ZDM
Sep 11, 2026
Patch Available
Sep 18, 2026