CVE-2026-8100 Details
Description
Impact A security issue has been identified in Chef 360 that could allow unauthorized access to protected API endpoints under specific conditions. This issue is due to improper handling of URL-encoded paths during request processing. In certain scenarios, an authenticated request may bypass standard access controls gaining additional privileges, potentially allowing access to API endpoints that are intended to be restricted to higher-permissioned roles. The impact is limited to environments where the affected request patterns can be triggered and depends on specific deployment configuration and access controls in place. Resolution The issue has been addressed through product updates that improve request validation and enforce strict path normalization before authorization checks. Customers are advised to update to the latest available version containing the fix, version 1.7.1 or later.
A vulnerability in Chef 360 has been identified that allows unauthorized access to protected API endpoints under certain conditions. This issue stems from improper handling of URL-encoded paths during request processing, which can enable an authenticated request to bypass standard access controls. As a result, additional privileges may be gained, potentially allowing access to API endpoints reserved for higher-permissioned roles. The vulnerability is limited to on-prem deployments of Chef 360 and depends on specific request patterns, deployment configurations, and access controls.
Users are advised to update to Chef 360 version 1.7.1 or later, which includes a fix for this vulnerability. If an immediate upgrade is not possible, consider restricting access to the affected API endpoints, applying additional filtering or validation at the network ingress, and monitoring for unusual API request patterns involving encoded URLs.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jun 18, 2026CISA-ADP
Assessed Jun 22, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://community.progress.com/s/article/Authentication-Bypass-via-URL-Encoded-Path-Traversal | [email protected] | AdvisoryRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-23 | Relative Path Traversal | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Progress Chef 360 | All versions |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 22, 2026 | CVE Modified | CISA-ADP |
| Jun 18, 2026 | New CVE Received | [email protected] |
Volerion