Not a U.S. government website. NDD is an independent vulnerability database by Volerion and is not affiliated with or endorsed by NIST or NVD.
VOLERION
Volerion Security Research

NOT DEFERRED DATABASE

VULNERABILITIES

CVE-2026-8100 Details

ANALYZED


This CVE record has been analyzed and enriched by NVDAPI.com as an independent party.

Description

Impact A security issue has been identified in Chef 360 that could allow unauthorized access to protected API endpoints under specific conditions. This issue is due to improper handling of URL-encoded paths during request processing. In certain scenarios, an authenticated request may bypass standard access controls gaining additional privileges, potentially allowing access to API endpoints that are intended to be restricted to higher-permissioned roles. The impact is limited to environments where the affected request patterns can be triggered and depends on specific deployment configuration and access controls in place. Resolution The issue has been addressed through product updates that improve request validation and enforce strict path normalization before authorization checks.  Customers are advised to update to the latest available version containing the fix, version 1.7.1 or later.

Metrics

CVSS 3.x Severity and Vector Strings:

References to Advisories, Solutions, and Tools

By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.

Weakness Enumeration

CWE-IDCWE NameSource
CWE-23Relative Path Traversal[email protected]

Affected Products

ProductVersions
Progress Chef 360
All versions

CPE

  • No CPEs found in CPE dictionary for this product.

Remediation

  • Upgrade: 1.7.1moderate effort
  • Mitigation:low effort

    Restrict access to API endpoints to trusted networks.

  • Mitigation:low effort

    Apply additional filtering or validation at ingress (e.g., WAF rules).

  • Mitigation:low effort

    Monitor for unusual API request patterns involving encoded URLs.

Change History

2 change records found show changes


QUICK INFO

CVE Dictionary Entry:
CVE-2026-8100
NVD Published Date:
Jun 18, 2026
NVD Last Modified:
Jun 22, 2026
Source:
[email protected]
CVE-2026-8100 Details - Not Deferred