CVE 8.8 HIGH

Insecure Default Configuration in P4 Server_CVE-2026-6043

8.8 / 10
HIGH
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N

Description

P4 Server versions prior to 2026.1 are configured with insecure default settings that, when exposed to untrusted networks, allow unauthenticated attackers to create arbitrary user accounts, enumerate existing users, authenticate to accounts with no password set, and access depot contents via the built-in 'remote' user. These default settings, taken together, can lead to unauthorized access to source code repositories and other managed assets. The 2026.1 release, expected in May 2026, enforces secure-by-default configurations on upgrade and new installations

AI Analysis

Insecure default configuration in P4 Server allows unauthenticated attackers to create arbitrary user accounts and access depot contents

Basic Information

ID CVE-2026-6043
Source Perforce
Published Apr 24, 2026 at 11:02
Modified Apr 24, 2026 at 12:02

Affected Product

Vendor Perforce
Product Helix Core Server (P4D)
Affected Versions Perforce Helix Core Server (P4D) 0

CWE Classification

AI Assessment

AI Score 8.8 / 10
AI Severity High
Vendor Perforce
Product Helix Core Server (P4D)
Version prior to 2026.1

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.