Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 05 Oct 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 05 Oct 2026 09:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | P4 Search prior to 2026.4.2 does not fail securely when its service authentication token is blank. In affected configurations, an unauthenticated attacker with network access can obtain the highest application privilege, potentially leading to compromise of P4 Search and the connected P4 Server. | |
| Title | Authentication bypass via blank auth token in P4Search | |
| Weaknesses | CWE-636 | |
| References |
| |
| Metrics |
cvssV4_0
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: Perforce
Published:
Updated: 2026-10-05T12:17:56.278Z
Reserved: 2026-09-30T17:38:12.196Z
Link: CVE-2026-103510
Updated: 2026-10-05T12:17:49.228Z
Status : Received
Published: 2026-10-05T09:17:06.977
Modified: 2026-10-05T13:16:50.733
Link: CVE-2026-103510
No data.
OpenCVE Enrichment
Updated: 2026-10-05T10:30:18Z
-
CWE-636
Not Failing Securely ('Failing Open')