CVE-2026-103510
Received Received - Intake

P4 Search Authentication Token Bypass Leads to Privilege Escalation

Vulnerability report for CVE-2026-103510, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-05

Last updated on: 2026-10-05

Assigner: Perforce

Description

P4 Search prior to 2026.4.2 does not fail securely when its service authentication token is blank. In affected configurations, an unauthenticated attacker with network access can obtain the highest application privilege, potentially leading to compromise of P4 Search and the connected P4 Server.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-05
Last Modified
2026-10-05
Generated
2026-10-05
AI Q&A
2026-10-05
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
puppet p4_search to 2026.4.2 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-636 When the product encounters an error condition or failure, its design requires it to fall back to a state that is less secure than other options that are available, such as selecting the weakest encryption algorithm or using the most permissive access control restrictions.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

P4 Search versions before 2026.4.2 fail to enforce secure authentication when its service token is blank. This allows an unauthenticated attacker with network access to gain the highest application privileges, potentially compromising both P4 Search and the connected P4 Server.

Impact Analysis

An attacker could exploit this to gain full control over P4 Search and the connected P4 Server, leading to unauthorized access, data theft, or system manipulation. This could result in complete compromise of sensitive data and operations.

Compliance Impact

This vulnerability could lead to unauthorized access and data breaches, violating GDPR and HIPAA requirements for data protection and access controls. Non-compliance may result in legal penalties and reputational damage.

Mitigation Strategies

Update P4 Search to version 2026.4.2 or later to address the insecure token handling. Ensure service authentication tokens are properly configured and not blank. Restrict network access to P4 Search services to trusted sources only.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-103510. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart