CVE-2026-6043 Details
Description
P4 Server versions prior to 2026.1 are configured with insecure default settings that, when exposed to untrusted networks, allow unauthenticated attackers to create arbitrary user accounts, enumerate existing users, authenticate to accounts with no password set, and access depot contents via the built-in 'remote' user. These default settings, taken together, can lead to unauthorized access to source code repositories and other managed assets. The 2026.1 release, expected in May 2026, enforces secure-by-default configurations on upgrade and new installations
A vulnerability exists in P4 Server (P4D) versions prior to 2026.1, where insecure default settings allow unauthenticated attackers to create arbitrary user accounts, enumerate existing users, and access depot contents through the built-in 'remote' user. This vulnerability arises when the server is exposed to untrusted networks, leading to unauthorized access to source code repositories and other managed assets.
Users of P4 Server (P4D) versions prior to 2026.1 should manually configure security-related server settings to harden their installation. Instructions for applying these security enhancements are available in the P4 Server Security Guidelines. The 2026.1 release will include automatic remediation for this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No CVSS 3.x data is available for this CVE.
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 24, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-1188 | Initialization of a Resource with an Insecure Default | [email protected] |
Affected Products
No affected product data is available for this CVE.
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 28, 2026 | CVE Modified | [email protected] |
| Apr 24, 2026 | New CVE Received | [email protected] |