Perforce patches CVSS 10 flaw that leaves P4 Search containers on a documented default token

Perforce has fixed six flaws in P4 Search, including a maximum-severity authentication bypass that hands unauthenticated attackers the highest privilege on the service.

Perforce patches CVSS 10 flaw that leaves P4 Search containers on a documented default token

At a glance

  • CVE-2026-100103 (CVSS 10.0) resets the P4 Search service auth token to a publicly documented default in container images
  • Two further critical flaws allow RCE via an exposed JDWP agent and a bypass using a blank token
  • All P4 Search versions up to and including 2026.4.1 are affected; 2026.4.2 is the fix
  • No in-the-wild exploitation has been confirmed, and credentials should be rotated after patching

Perforce has released P4 Search 2026.4.2 to fix six vulnerabilities, the most serious of which is rated CVSS 10.0 and lets an unauthenticated attacker take full control of the search service and potentially the source code server behind it. The fixes were reported by securityonline.info on 5 October 2026, and the flaw's details appear in its CVE record published the same day.

What happened

According to the CVE record for CVE-2026-100103, P4 Search container images released before 2026.4.2 reset the service authentication token to a publicly documented default value. Because that value is in the vendor's own documentation, an attacker who can reach the service over the network needs nothing else. The record states that this grants the highest application privilege and can lead to arbitrary code execution and compromise of the connected P4 Server. The flaw is classified as CWE-1392, use of default credentials, with a CVSS 10.0 base score.

P4 Search is the indexing and search component that sits alongside Perforce's P4 (Helix Core) version control server — the system of record for source code in many game, automotive and semiconductor development organisations. A compromise of the search tier is therefore not an isolated problem.

Technical details

securityonline.info reports six issues fixed in 2026.4.2, all affecting P4 Search 2026.4.1 and earlier:

  • CVE-2026-100103 — CVSS 10.0, authentication bypass via the default auth token described above
  • CVE-2026-100102 — CVSS 9.5, remote code execution through an exposed JDWP debug agent
  • CVE-2026-103510 — CVSS 9.5, authentication bypass using a blank auth token
  • CVE-2026-103507 — CVSS 7.5, arbitrary file write via the logging configuration
  • CVE-2026-103512 — CVSS 5.3, ticket host-binding bypass using a spoofed source IP
  • CVE-2026-103511 — CVSS 5.1, arbitrary file write via the extension installer

The exposed Java Debug Wire Protocol agent in CVE-2026-100102 is a classic deployment defect: JDWP offers no authentication by design, so any reachable debug port is effectively a code execution interface. According to securityonline.info, five of the six flaws were identified by researcher Khoa Bui.

Who is affected

Every P4 Search deployment at 2026.4.1 or earlier is in scope. The maximum-severity issue is specific to container images, which makes containerised and Kubernetes-based installations the priority. securityonline.info reports that no exploitation in the wild has been confirmed so far.

What to do

Upgrade P4 Search to 2026.4.2. Patching alone is not sufficient for the default-token issue: because the token may be a known value, set a strong and unique service authentication token after the upgrade and rotate any credentials the service held.

In the meantime, confirm that neither the P4 Search service nor any JDWP debug port is reachable from untrusted networks, and restrict access to the hosts that legitimately need it. Review the service's access logs for authentication attempts that succeeded without an expected token value, and check whether the logging configuration or extension installer paths were modified.

Related CVEs

Sources

This story is based on the sources listed above. Always check the vendor’s official advisory before acting on critical systems.