PT-2026-50803 · Chef 360 · Chef360
CVE-2026-8100
·
Published
2026-06-18
·
Updated
2026-06-19
CVSS v4.0
8.6
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:N/AU:Y/R:X/V:X/RE:M/U:X |
Name of the Vulnerable Software and Affected Versions
Chef 360 versions prior to 1.7.1
Description
Improper handling of URL-encoded paths during request processing can allow unauthorized access to protected API endpoints. An authenticated request may bypass standard access controls to gain additional privileges, potentially granting access to API endpoints intended for higher-permissioned roles. This occurs due to a failure in path normalization, which is the process of converting a path to a standard format to ensure consistent security checks.
Recommendations
Update to version 1.7.1 or later.
Fix
Relative Path Traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Chef360