Impact
The flaw exists in P4 Search versions prior to 2026.4.2, where the service authentication token is accepted even when it is blank. This allows an unauthenticated attacker to authenticate with the highest possible privileges, effectively compromising the entire P4 Search service and potentially the connected P4 Server. The weakness is a classic example of improper authentication and is listed as CWE-636 for invalid input handling.
Affected Systems
Perforce P4 (Helix Core) users that deploy P4 Search before the 2026.4.2 release are affected. The vulnerability is inherent in the configuration that permits a blank authentication token, regardless of the specific minor version within that pre‑release window.
Risk and Exploitability
The CVSS score of 9.5 indicates critical severity. EPSS data is not available, so the exact exploitation probability cannot be quantified, but the vulnerability is listed outside the CISA KEV catalog. Attackers with network access to the P4 Search service can exploit this flaw over the network without any authentication, making the attack vector local to the network where the service is exposed. Successful exploitation results in full administrative control of the P4 Search instance and, by extension, the underlying P4 Server.
OpenCVE Enrichment