CVE-2026-6043General

LOWCVSS 8.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

P4 Server versions prior to 2026.1 are configured with insecure default settings that, when exposed to untrusted networks, allow unauthenticated attackers to create arbitrary user accounts, enumerate existing users, authenticate to accounts with no password set, and access depot contents via the built-in 'remote' user. These default settings, taken together, can lead to unauthorized access to source code repositories and other managed assets. The 2026.1 release, expected in May 2026, enforces secure-by-default configurations on upgrade and new installations

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-1188

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • General: 1 classified signal
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-04-24); latest day: 1
  • 2 total mentions across 2 days

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-04-24: 1Mentions · 2026-04-25: 1Technical Details · 2026-04-24: 1Technical Details · 2026-04-25: 104-2404-25
Signal classification2 categories
General
150.0%
Disclosure
150.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-04-241
General1
2026-04-251
Disclosure1
Full discourse2 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-6043 P4 Server versions prior to 2026.1 are configured with insecure default settings that, when exposed to untrusted networks, allow unauthenticated attackers to create arb… https://www.cve.org/CVERecord?id=CVE-2026-6043

    Post summary

    The text announces CVE‑2026‑6043 as a vulnerability involving insecure default settings that allow unauthenticated attackers to create arbitrary entities, but it provides no evidence of a PoC, exploit code, active exploitation, or patch.

    0001095
    57.2K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-6043 Unauthenticated Unauthorized Access in Perforce P4 Server Versions Prior ... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-6043 Vulnerability Notification: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=3

    Post summary

    The post is a brief vulnerability notice for CVE-2026‑6043 that highlights unauthenticated access in older Perforce P4 Server versions, but provides only generic links and no exploit, patch, or active exploitation details.

    0000052
    4.0K followersView on X

Explore more