A static credential embedded in Chef 360 prior to v1.7.0 permitted unauthenticated access to internal message queues.  Queue messages contained tenant-specific identifiers.  The credential has been rotated and replaced with per-tenant access in subsequent versions, eliminating this access method entirely.

Project Subscriptions

Vendors Products
Progress Subscribe
Chef360 Subscribe
Advisories

No advisories yet.

Fixes

Solution

Fixed in 1.7.1


Workaround

Remove content from bundled tools; change password

References
History

Mon, 22 Jun 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 21 Jun 2026 09:45:00 +0000

Type Values Removed Values Added
First Time appeared Progress
Progress chef360
Vendors & Products Progress
Progress chef360

Thu, 18 Jun 2026 22:00:00 +0000

Type Values Removed Values Added
Description A static credential embedded in Chef 360 prior to v1.7.0 permitted unauthenticated access to internal message queues.  Queue messages contained tenant-specific identifiers.  The credential has been rotated and replaced with per-tenant access in subsequent versions, eliminating this access method entirely.
Title Hardcoded credentials in embedded content
Weaknesses CWE-523
References
Metrics cvssV4_0

{'score': 2.3, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:L/VI:N/VA:L/SC:H/SI:N/SA:L/E:P/S:N/AU:Y/RE:L'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: ProgressSoftware

Published:

Updated: 2026-06-22T18:23:03.280Z

Reserved: 2026-05-15T09:51:14.946Z

Link: CVE-2026-8668

cve-icon Vulnrichment

Updated: 2026-06-22T18:22:59.066Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-20T22:55:38Z

Weaknesses