CVE-2026-103512Medium· 5.3▾ SunlitPerforce P4 Search prior to 2026.4.2 trusts a client-supplied address when validating certain authentication requests. An attacker holding a stolen P4 Server ticket can bypass host-based ticket restrictions and trusted-address controls, …
▾ Sunlit zone — Low / medium · no exploitation signal
impact 29.2 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Perforce P4 Search prior to 2026.4.2 trusts a client-supplied address when validating certain authentication requests. An attacker holding a stolen P4 Server ticket can bypass host-based ticket restrictions and trusted-address controls, gaining access to P4 Search as the ticket's owner.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-100103Critical· 10.0Perforce P4 Search container images prior to 2026.4.2 reset the service authentication token to a publicly documented default value
CVE-2026-103507High· 7.5Perforce P4 Search prior to 2026.4.2 does not restrict file paths written through its logging configuration interface
CVE-2026-100102Critical· 9.5Perforce P4 Search container images prior to 2026.4.2 enable an unauthenticated Java debug interface
CVE-2026-103511Medium· 5.1Perforce P4 Search prior to 2026.4.2 does not validate file names supplied to its extension installation feature
CVE-2026-103510Critical· 9.5P4 Search prior to 2026.4.2 does not fail securely when its service authentication token is blank
CVE-2025-14327High· 7.5Spoofing issue in the Downloads Panel component