Description
P4 Search prior to 2026.4.2 does not fail securely when its service authentication token is blank. In affected configurations, an unauthenticated attacker with network access can obtain the highest application privilege, potentially leading to compromise of P4 Search and the connected P4 Server.
Published: 2026-10-05
Score: 9.5 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Authentication bypass allowing an unauthenticated attacker to gain highest application privilege
Action: Immediate Patch
AI Analysis

Impact

The flaw exists in P4 Search versions prior to 2026.4.2, where the service authentication token is accepted even when it is blank. This allows an unauthenticated attacker to authenticate with the highest possible privileges, effectively compromising the entire P4 Search service and potentially the connected P4 Server. The weakness is a classic example of improper authentication and is listed as CWE-636 for invalid input handling.

Affected Systems

Perforce P4 (Helix Core) users that deploy P4 Search before the 2026.4.2 release are affected. The vulnerability is inherent in the configuration that permits a blank authentication token, regardless of the specific minor version within that pre‑release window.

Risk and Exploitability

The CVSS score of 9.5 indicates critical severity. EPSS data is not available, so the exact exploitation probability cannot be quantified, but the vulnerability is listed outside the CISA KEV catalog. Attackers with network access to the P4 Search service can exploit this flaw over the network without any authentication, making the attack vector local to the network where the service is exposed. Successful exploitation results in full administrative control of the P4 Search instance and, by extension, the underlying P4 Server.

Generated by OpenCVE AI on October 5, 2026 at 10:25 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to P4 Search version 2026.4.2 or later, which enforces a non‑blank authentication token.
  • Configure the service to reject any blank authentication tokens, ensuring that only valid tokens are accepted.
  • Restrict network access to the P4 Search service so that only trusted hosts in a segmented environment can reach it, reducing the attacker footprint.

Generated by OpenCVE AI on October 5, 2026 at 10:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 05 Oct 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 05 Oct 2026 09:00:00 +0000

Type Values Removed Values Added
Description P4 Search prior to 2026.4.2 does not fail securely when its service authentication token is blank. In affected configurations, an unauthenticated attacker with network access can obtain the highest application privilege, potentially leading to compromise of P4 Search and the connected P4 Server.
Title Authentication bypass via blank auth token in P4Search
Weaknesses CWE-636
References
Metrics cvssV4_0

{'score': 9.5, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Perforce

Published:

Updated: 2026-10-05T12:17:56.278Z

Reserved: 2026-09-30T17:38:12.196Z

Link: CVE-2026-103510

cve-icon Vulnrichment

Updated: 2026-10-05T12:17:49.228Z

cve-icon NVD

Status : Received

Published: 2026-10-05T09:17:06.977

Modified: 2026-10-05T13:16:50.733

Link: CVE-2026-103510

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-05T10:30:18Z

Weaknesses
  • CWE-636

    Not Failing Securely ('Failing Open')