CVE-2026-80462EPSS p39.4%

CVE-2026-80462CVE-2026-80462

Description

A vulnerability in the Chef Automate API gateway and identity validation path may allow an unauthenticated actor to gain elevated access to protected Chef Automate functionality under specific conditions.

Scoring

CVSS 10.0 ()
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
EPSS0.48% probability of exploitation · percentile 39.4% · 2026-10-05T12:00:23Z
Last modified2026-09-18
Sourced from NVD + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.