PatchSiren cyber security CVE debrief
CVE-2026-103512 Perforce CVE debrief
The Perforce P4 Search vulnerability prior to 2026.4.2 allows an attacker holding a stolen P4 Server ticket to bypass host-based ticket restrictions and trusted-address controls, gaining access to P4 Search as the ticket's owner. This issue affects Perforce P4 Search administrators and users with access to P4 Server tickets. The CVE record was published on 2026-10-05T09:17:07.247Z and has not been modified since then. The vulnerability requires verification of the 2026.4.2 update to ensure the bypass is addressed. Administrators should review and restrict access to P4 Server tickets to prevent exploitation.
- Vendor
- Perforce
- Product
- P4 (Helix Core)
- CVSS
- MEDIUM 5.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-05
- Original CVE updated
- 2026-10-05
- Advisory published
- 2026-10-05
- Advisory updated
- 2026-10-05
Who should care
Perforce P4 Search administrators and users with access to P4 Server tickets should assess exposure and verify the 2026.4.2 update. Affected operator, platform, vulnerability-management, and security-team impact should be reviewed to ensure proper mitigation. Review and restrict access to P4 Server tickets to prevent exploitation.
Why it matters
CVE-2026-103512 allows an attacker with a stolen P4 Server ticket to bypass host-based ticket restrictions and trusted-address controls in Perforce P4 Search prior to 2026.4.2, potentially leading to unauthorized access.
- An attacker can bypass host-based ticket restrictions and trusted-address controls to gain unauthorized access to P4 Search.
- The vulnerability requires verification of the 2026.4.2 update to ensure the bypass is addressed.
- Administrators should review and restrict access to P4 Server tickets to prevent exploitation.
Technical summary
The Perforce P4 Search vulnerability prior to 2026.4.2 allows an attacker holding a stolen P4 Server ticket to bypass host-based ticket restrictions and trusted-address controls, gaining access to P4 Search as the ticket's owner. This issue requires verification of the 2026.4.2 update to ensure the bypass is addressed. The vulnerability affects Perforce P4 Search administrators and users with access to P4 Server tickets. The official CVE Program record and NIST NVD detail page offer source-provided CVE metadata and vulnerability assessments.
Defensive priority
Perforce P4 Search administrators should verify and apply the 2026.4.2 update to address the host-based ticket restrictions and trusted-address controls bypass vulnerability.
Recommended defensive actions
- Verify and apply the 2026.4.2 update for Perforce P4 Search
- Review and restrict access to P4 Server tickets
- Monitor P4 Search authentication requests for suspicious activity
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
Evidence notes
The CVE record and NVD entry provide details on the vulnerability in Perforce P4 Search prior to 2026.4.2, which allows an attacker with a stolen P4 Server ticket to bypass host-based ticket restrictions and trusted-address controls. The official CVE Program record and NIST NVD detail page offer source-provided CVE metadata and vulnerability assessments. The source reference for CVE-2026-103512 also provides additional context.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-103512 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-103512
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-103512 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-103512
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://portal.perforce.com/s/cve/a91Qi000003FDo1IAG/ticket-hostbinding-bypass-via-spoofed-client-ip-in-p4search
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.