Insecure Default Configuration in P4 Server by Perforce
CVE-2026-6043

8.8HIGH

Key Information:

Vendor

Perforce

Vendor
CVE Published:
24 April 2026

What is CVE-2026-6043?

P4 Server versions prior to 2026.1 are shipped with insecure default settings that can leave installations vulnerable to unauthorized access. When these configurations are exposed to untrusted networks, attackers can exploit them to create arbitrary user accounts, enumerate existing users, and authenticate to accounts that do not have passwords set. This can lead to unauthorized access to sensitive depot contents and source code repositories. The release of version 2026.1 addresses these vulnerabilities by enforcing secure-by-default configurations.

Affected Version(s)

Helix Core Server (P4D) 0 <= 2025.2

References

CVSS V4

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.