CVE-2026-8668
Received Received - Intake
Chef 360 Static Credential in Message Queue

Publication date: 2026-06-18

Last updated on: 2026-06-18

Assigner: Progress Software Corporation

Description
A static credential embedded in Chef 360 prior to v1.7.0 permitted unauthenticated access to internal message queues.  Queue messages contained tenant-specific identifiers.  The credential has been rotated and replaced with per-tenant access in subsequent versions, eliminating this access method entirely.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-06-18
Last Modified
2026-06-18
Generated
2026-06-19
AI Q&A
2026-06-19
EPSS Evaluated
N/A
NVD
EUVD
Affected Vendors & Products
Showing 1 associated CPE
Vendor Product Version / Range
progress chef to 1.7.0 (exc)
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-523 Login pages do not use adequate measures to protect the user name and password while they are in transit from the client to the server.
Attack-Flow Graph
AI Quick Actions
Instant insights powered by AI
Executive Summary

This vulnerability involves a static credential embedded in Chef 360 versions prior to 1.7.0 that allowed unauthenticated access to internal message queues.

These message queues contained tenant-specific identifiers, meaning that unauthorized users could potentially access information related to different tenants.

The issue was addressed by rotating the static credential and replacing it with per-tenant access controls in later versions, which eliminated this unauthorized access method.

Impact Analysis

The vulnerability could allow unauthorized users to access internal message queues without authentication.

Since these queues contain tenant-specific identifiers, this could lead to exposure of sensitive tenant information or identifiers.

Such unauthorized access might compromise tenant data confidentiality and potentially lead to further security risks depending on the information accessed.

Mitigation Strategies

To mitigate this vulnerability, upgrade Chef 360 to version 1.7.0 or later, where the static credential has been rotated and replaced with per-tenant access, eliminating the unauthenticated access to internal message queues.

Chat Assistant
Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-8668. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70
EPSS Chart