Authentication Bypass Vulnerability in P4 Search by Perforce
CVE-2026-103510

9.5CRITICAL

Key Information:

Vendor

Perforce

Vendor
CVE Published:
5 October 2026

What is CVE-2026-103510?

The P4 Search application by Perforce, specifically versions prior to 2026.4.2, presents an authentication bypass issue. The service fails to properly secure its authentication token, allowing an unauthenticated attacker with network access to exploit this vulnerability. This could enable them to gain the highest application privilege, which may lead to the compromise of both P4 Search and the associated P4 Server, facilitating unauthorized access to sensitive data and application functions.

Affected Version(s)

P4 (Helix Core) 0 <= 2026.4.1

P4 (Helix Core) 0 <= 2026.4.1

P4 (Helix Core) 2026.4.2

References

CVSS V4

Score:
9.5
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Khoa Bui (https://github.com/zenniskayy2k4) finder
.