External risk intelligence

P4 Search Blank Token Authentication Bypass

CVE advisorySeverity: CRITICAL (CVSS 9.5)

CVE-2026-103510

P4 Search is typically deployed as a search indexing and retrieval service within an internal development environment to support P4 Server. While it is a network-accessible service, it is generally intended for internal team access rather than public internet exposure. Public reachability depends on specific organizational network configurations.

Halo Surface Signal: 3 out of 5 — possibly public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A vulnerability in P4 Search allows an attacker to gain the highest level of access without needing to authenticate, potentially compromising the connected P4 Server. This could lead to a broad compromise of development tools if P4 Search is exposed to the network.

  • Unauthenticated access to highest privileges.
  • Secures development tools and intellectual property.
  • Confirm P4 Search network exposure.

Attack Path

How an attacker could exploit the issue

An attacker could leverage a blank service authentication token in P4 Search to bypass security controls. This initial access allows them to escalate their privileges to the highest level within the application, potentially leading to a compromise of both P4 Search and the connected P4 Server.

  • Network access needed.
  • Blank authentication token.
  • Highest application privilege.

Live Threat

Current exploitation, exposure, and threat context

When P4 Search is configured with a blank service authentication token and is network accessible, an unauthenticated attacker could gain the highest application privileges. This could lead to unauthorized control over P4 Search and any connected P4 Server, potentially impacting the integrity and availability of associated development data.

  • P4 Search and connected P4 Server data.
  • Unauthenticated network access to P4 Search.
  • Compromise of P4 Search and P4 Server.

Operational Fix

Recommended remediation, mitigation, and detection steps

The P4 Search service requires immediate attention due to an authentication bypass vulnerability. Given that P4 Search is typically integrated with P4 Server, likely falling under the purview of development platform or infrastructure teams, they should take the lead. The first practical step is to confirm the deployment scope of P4 Search, determine its network accessibility, and identify the business criticality of connected P4 Servers to prioritize remediation efforts.

  • Own by: Platform or Infrastructure teams.
  • Verify first: Network reachability and criticality.
  • Action: Plan and coordinate remediation.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is P4 Search and why is it used?

P4 Search is a specialized service designed to index and retrieve data from a P4 Server. Development teams use it to enable fast, efficient searching across large codebases and version-controlled assets stored in their Perforce environment, ensuring that engineers can quickly locate the files and project history they need.

What is the vulnerability in CVE-2026-103510?

This vulnerability is classified as CWE-636: Not Failing Securely. In technical terms, P4 Search fails to properly validate its service authentication token. If a token is left blank, the system does not reject the connection but instead defaults to granting the caller the highest possible application privileges, allowing an attacker to bypass authentication entirely.

How does an attacker trigger this authentication bypass?

An attacker triggers the flaw by sending requests to a P4 Search instance that has been configured with a blank authentication token. Crucially, the vulnerability does not trigger if a valid, non-blank service token is properly configured, as the system would then require authentication before processing requests.

Is my organization at risk from this P4 Search issue?

According to Halo Surface Signal, risk depends on your network configuration. While P4 Search is generally intended for internal use, it may be reachable if your organization has exposed it to wider networks. You should care if your P4 Search instance is accessible over a network where unauthorized parties could reach it, as this could lead to a compromise of the connected P4 Server.

What should I do if I am running P4 Search?

First, identify all P4 Search deployments in your environment and confirm their network accessibility. Assess whether these instances are exposed to untrusted networks and evaluate the criticality of the data on your connected P4 Servers. Coordinate with your infrastructure or platform teams to prioritize these instances for updates to ensure they are on version 2026.4.2 or later.

References