CVE-2026-8668 - Hardcoded credentials in embedded content
CVE ID :CVE-2026-8668
Published : June 18, 2026, 9:19 p.m. | 2 hours, 20 minutes ago
Description :A static credential embedded in Chef 360 prior to v1.7.0 permitted unauthenticated access to internal message queues. Queue messages contained tenant-specific identifiers. The credential has been rotated and replaced with per-tenant access in subsequent versions, eliminating this access method entirely.
Severity: 2.3 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Published : June 18, 2026, 9:19 p.m. | 2 hours, 20 minutes ago
Description :A static credential embedded in Chef 360 prior to v1.7.0 permitted unauthenticated access to internal message queues. Queue messages contained tenant-specific identifiers. The credential has been rotated and replaced with per-tenant access in subsequent versions, eliminating this access method entirely.
Severity: 2.3 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...