PT-2026-50803 · Chef 360 · Chef360

CVE-2026-8100

·

Published

2026-06-18

·

Updated

2026-06-19

CVSS v4.0

8.6

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:N/AU:Y/R:X/V:X/RE:M/U:X
Name of the Vulnerable Software and Affected Versions Chef 360 versions prior to 1.7.1
Description Improper handling of URL-encoded paths during request processing can allow unauthorized access to protected API endpoints. An authenticated request may bypass standard access controls to gain additional privileges, potentially granting access to API endpoints intended for higher-permissioned roles. This occurs due to a failure in path normalization, which is the process of converting a path to a standard format to ensure consistent security checks.
Recommendations Update to version 1.7.1 or later.

Fix

Relative Path Traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-8100

Affected Products

Chef360