CVE-2026-103512EPSS p29.3%
CVE-2026-103512CVE-2026-103512
Description
Perforce P4 Search prior to 2026.4.2 trusts a client-supplied address when validating certain authentication requests. An attacker holding a stolen P4 Server ticket can bypass host-based ticket restrictions and trusted-address controls, gaining access to P4 Search as the ticket's owner.
Scoring
| EPSS | 0.37% probability of exploitation · percentile 29.3% · 2026-10-10T12:00:23Z |
| Last modified | 2026-10-06 |