CVE-2026-80462

A vulnerability in the Chef Automate API gateway and identity validation path may allow an unauthenticated actor to gain elevated access to protected Chef Automate functionality under specific conditions.

  • Published Sep 11, 2026
  • CVSS 10.0 critical
  • 0.5% chance of exploitation in the next 30 days (EPSS)

Affected software

CVE-2026-80462 at the National Vulnerability Database