Impact
Perforce Helix Core’s P4 Search component, before 2026.4.2, incorrectly trusts a client‑supplied IP address when validating certain authentication requests. An attacker in possession of a stolen, valid P4 Server ticket can exploit this flaw to bypass host‑based ticket restrictions and trusted‑address controls, effectively gaining the privileges of the ticket owner. The weakness is an example of improper authentication trust, classified as CWE‑290, and results in an unauthorized access vulnerability that could allow an attacker to read, modify, or delete data in the P4 repository as the ticket holder.
Affected Systems
The affected product is Perforce Helix Core (P4). All installations running P4 Search prior to release 2026.4.2 are vulnerable. No specific sub‑versions are listed beyond the release boundary; users must check their local build against 2026.4.2 or later to confirm remediation.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate severity. Because the EPSS score is not available, the likelihood of exploitation is uncertain, and the vulnerability is not listed in CISA's KEV catalog, the overall risk is moderate but still actionable. The attack requires possession of a valid, stolen P4 Server ticket and the ability to send requests to the vulnerable P4 Search instance. Successful exploitation would allow the attacker to use the ticket as if they were the legitimate user, bypassing host restrictions and potentially compromising confidential repository data.
OpenCVE Enrichment