---
id: CVE-2026-103510
title: >-
  P4 Search prior to 2026.4.2 does not fail securely when its service
  authentication token is blank
summary: >-
  P4 Search prior to 2026.4.2 does not fail securely when its service
  authentication token is blank. In affected configurations, an unauthenticated
  attacker with network access can obtain the highest application privilege,
  potentially lead…
severity: critical
cvss: 9.5
cvssVector: 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'
cwe:
  - CWE-636
vendor: Perforce
product: P4Search
affected:
  - P4Search <= 2026.4.1
published: '2026-10-05'
updated: '2026-10-05'
sourceUpdated: '2026-10-05T13:16:50.733'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-103510'
references:
  - url: >-
      https://portal.perforce.com/s/cve/a91Qi000003FDw5IAG/authentication-bypass-via-blank-auth-token-in-p4search
    label: security@puppet.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-10-05T12:17:31.735930Z'
cvssSource: cna
ingestedAt: '2026-10-05T09:16:17.864Z'
epss: 0.00348
epssPercentile: 0.26145
---

## Overview

P4 Search prior to 2026.4.2 does not fail securely when its service authentication token is blank. In affected configurations, an unauthenticated attacker with network access can obtain the highest application privilege, potentially leading to compromise of P4 Search and the connected P4 Server.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
