Summary
CVE-2026-103510 is an authentication bypass vulnerability in Perforce P4 Search, the search component bundled with P4 (Helix Core). The component fails to fail securely when its service authentication token is left blank, allowing an unauthenticated, network-based attacker to obtain the highest application privilege within P4 Search. This can lead to full compromise of P4 Search and the connected P4 Server, and Perforce has rated the issue Critical (CVSS 9.5).
Technical details
- Root cause: P4 Search validates requests using a service authentication token, but when that token is configured as blank (empty), the component does not reject the request — it "fails open" rather than failing securely (CWE-636: Not Failing Securely).
- Trigger conditions: The flaw manifests "in affected configurations" where the P4 Search service authentication token has been left blank, which removes the intended authentication check entirely.
- Attack vector: Network — no authentication or user interaction is required; an attacker only needs network access to the exposed P4 Search service.
- Impact: A successful attacker can obtain the highest application privilege within P4 Search, enabling compromise of the P4 Search instance and, through its connection, the backing P4 Server — threatening confidentiality, integrity, and availability of source code and related data.
Affected software
- Perforce P4 (Helix Core) — P4Search component, versions 0 through 2026.4.1 (i.e., all versions prior to 2026.4.2) where the service authentication token is blank.
- Fixed in P4Search 2026.4.2.
Severity
- CVSS v4.0 Base Score: 9.5 (Critical)
- Vector:
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H - Attack Vector: Network, Attack Complexity: Low, Privileges Required: None, User Interaction: None, with High impact to Confidentiality, Integrity, and Availability.
Mitigation and recommended actions
- Immediate: Upgrade P4 Search to version 2026.4.2 or later, which addresses the insecure fail-open behavior.
- If immediate patching is not possible: Ensure the P4 Search service authentication token is explicitly configured with a strong, non-blank value, and restrict network access to the P4 Search service to trusted hosts/networks only (e.g., via firewall rules or network segmentation) until the patch can be applied.
- Review P4 Search and P4 Server logs for unexpected or unauthenticated access patterns as part of incident response.

