vulnti.work

A vulnerability in the Chef Automate API gateway and identity validation path may allow an unauthenticated actor to gain elevated access to protected Chef Automate functionality under specific condit…

Critical CVSS 10.0
CVECVE-2026-80462
First seen2026-09-18 20:16 UTC
Disclosed2026-09-11 13:18 UTC
Last updated2026-09-18 20:16 UTC
Channel statusauto

Summary

A vulnerability in the Chef Automate API gateway and identity validation path may allow an unauthenticated actor to gain elevated access to protected Chef Automate functionality under specific conditions.

In-depth triage

No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).

Sources

  • NVD DATABASE

Original Links

Timeline

  1. nvd_ingest NVD