Description
Perforce P4 Search prior to 2026.4.2 trusts a client-supplied address when validating certain authentication requests. An attacker holding a stolen P4 Server ticket can bypass host-based ticket restrictions and trusted-address controls, gaining access to P4 Search as the ticket's owner.
Published: 2026-10-05
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Access via Ticket Bypass
Action: Patch Now
AI Analysis

Impact

Perforce Helix Core’s P4 Search component, before 2026.4.2, incorrectly trusts a client‑supplied IP address when validating certain authentication requests. An attacker in possession of a stolen, valid P4 Server ticket can exploit this flaw to bypass host‑based ticket restrictions and trusted‑address controls, effectively gaining the privileges of the ticket owner. The weakness is an example of improper authentication trust, classified as CWE‑290, and results in an unauthorized access vulnerability that could allow an attacker to read, modify, or delete data in the P4 repository as the ticket holder.

Affected Systems

The affected product is Perforce Helix Core (P4). All installations running P4 Search prior to release 2026.4.2 are vulnerable. No specific sub‑versions are listed beyond the release boundary; users must check their local build against 2026.4.2 or later to confirm remediation.

Risk and Exploitability

The CVSS score of 5.3 indicates a moderate severity. Because the EPSS score is not available, the likelihood of exploitation is uncertain, and the vulnerability is not listed in CISA's KEV catalog, the overall risk is moderate but still actionable. The attack requires possession of a valid, stolen P4 Server ticket and the ability to send requests to the vulnerable P4 Search instance. Successful exploitation would allow the attacker to use the ticket as if they were the legitimate user, bypassing host restrictions and potentially compromising confidential repository data.

Generated by OpenCVE AI on October 5, 2026 at 10:28 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Perforce Helix Core to version 2026.4.2 or later, which eliminates the host‑binding bypass flaw.
  • If an upgrade is not immediately possible, restrict P4 Search access to trusted networks only and block incoming requests that include forged client IP headers by applying firewall rules.
  • Verify that host‑based ticket restrictions and trusted‑address controls are correctly enforced by reviewing the P4 Search configuration and, if supported, disabling any option that allows client‑supplied IP addresses to be trusted in authentication.

Generated by OpenCVE AI on October 5, 2026 at 10:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 05 Oct 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 05 Oct 2026 09:00:00 +0000

Type Values Removed Values Added
Description Perforce P4 Search prior to 2026.4.2 trusts a client-supplied address when validating certain authentication requests. An attacker holding a stolen P4 Server ticket can bypass host-based ticket restrictions and trusted-address controls, gaining access to P4 Search as the ticket's owner.
Title Ticket host-binding bypass via spoofed client IP in P4Search
Weaknesses CWE-290
References
Metrics cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Perforce

Published:

Updated: 2026-10-05T12:34:32.028Z

Reserved: 2026-09-30T17:38:18.505Z

Link: CVE-2026-103512

cve-icon Vulnrichment

Updated: 2026-10-05T12:32:50.875Z

cve-icon NVD

Status : Received

Published: 2026-10-05T09:17:07.247

Modified: 2026-10-05T13:16:50.993

Link: CVE-2026-103512

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-05T10:30:18Z

Weaknesses
  • CWE-290

    Authentication Bypass by Spoofing