CVE-2026-8668 Details
Description
A static credential embedded in Chef 360 prior to v1.7.0 permitted unauthenticated access to internal message queues. Queue messages contained tenant-specific identifiers. The credential has been rotated and replaced with per-tenant access in subsequent versions, eliminating this access method entirely.
A vulnerability in Progress Chef 360 Platform prior to version 1.7.0 allowed unauthenticated access to internal message queues due to a static credential embedded in the application. The queue messages contained tenant-specific identifiers. This access method has been eliminated in version 1.7.0 and later, where the credential was rotated and replaced with per-tenant access.
Users can upgrade to Chef 360 Platform version 1.7.0 or later to address this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jun 18, 2026CISA-ADP
Assessed Jun 22, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://docs.chef.io/release_notes/360/ | [email protected] | Release NotesVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-523 | Unprotected Transport of Credentials | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Progress Chef 360 | < 1.7.0 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 22, 2026 | CVE Modified | CISA-ADP |
| Jun 18, 2026 | New CVE Received | [email protected] |
Volerion