Impact
A race condition in the lockout mechanism allowed the lockout threshold to be bypassed through concurrent authentication requests. Parallel login attempts were processed before the failed‑login counter and lockout status were updated, defeating brute‑force protections and enabling continued password guessing against a targeted account.
Affected Systems
Perforce Delphix Continuous Data is affected. No specific version information is provided in the CNA data, so deployments should verify whether they are running a version older than the patched 2026.4.0.0 release.
Risk and Exploitability
The CVSS score of 8.3 indicates high severity, and the EPSS score of less than 1% indicates a very low but non‑zero exploitation probability. The likely attack vector is sending multiple simultaneous authentication requests to the affected service from any system with network reach to the authentication endpoint. Because the race condition prevents the lockout counter and status from updating properly, an attacker can repeatedly guess passwords until successful authentication, potentially leading to unauthorized access to the data managed by Delphix Continuous Data. This vulnerability is not listed in the CISA KEV catalog.
OpenCVE Enrichment