Perforce patches CVSS 10 flaw that leaves P4 Search containers on a documented default token
Perforce has fixed six flaws in P4 Search, including a maximum-severity authentication bypass that hands unauthenticated attackers the highest privilege on the service.
At a glance
- CVE-2026-100103 (CVSS 10.0) resets the P4 Search service auth token to a publicly documented default in container images
- Two further critical flaws allow RCE via an exposed JDWP agent and a bypass using a blank token
- All P4 Search versions up to and including 2026.4.1 are affected; 2026.4.2 is the fix
- No in-the-wild exploitation has been confirmed, and credentials should be rotated after patching
Perforce has released P4 Search 2026.4.2 to fix six vulnerabilities, the most serious of which is rated CVSS 10.0 and lets an unauthenticated attacker take full control of the search service and potentially the source code server behind it. The fixes were reported by securityonline.info on 5 October 2026, and the flaw's details appear in its CVE record published the same day.
What happened
According to the CVE record for CVE-2026-100103, P4 Search container images released before 2026.4.2 reset the service authentication token to a publicly documented default value. Because that value is in the vendor's own documentation, an attacker who can reach the service over the network needs nothing else. The record states that this grants the highest application privilege and can lead to arbitrary code execution and compromise of the connected P4 Server. The flaw is classified as CWE-1392, use of default credentials, with a CVSS 10.0 base score.
P4 Search is the indexing and search component that sits alongside Perforce's P4 (Helix Core) version control server — the system of record for source code in many game, automotive and semiconductor development organisations. A compromise of the search tier is therefore not an isolated problem.
Technical details
securityonline.info reports six issues fixed in 2026.4.2, all affecting P4 Search 2026.4.1 and earlier:
CVE-2026-100103— CVSS 10.0, authentication bypass via the default auth token described aboveCVE-2026-100102— CVSS 9.5, remote code execution through an exposed JDWP debug agentCVE-2026-103510— CVSS 9.5, authentication bypass using a blank auth tokenCVE-2026-103507— CVSS 7.5, arbitrary file write via the logging configurationCVE-2026-103512— CVSS 5.3, ticket host-binding bypass using a spoofed source IPCVE-2026-103511— CVSS 5.1, arbitrary file write via the extension installer
The exposed Java Debug Wire Protocol agent in CVE-2026-100102 is a classic deployment defect: JDWP offers no authentication by design, so any reachable debug port is effectively a code execution interface. According to securityonline.info, five of the six flaws were identified by researcher Khoa Bui.
Who is affected
Every P4 Search deployment at 2026.4.1 or earlier is in scope. The maximum-severity issue is specific to container images, which makes containerised and Kubernetes-based installations the priority. securityonline.info reports that no exploitation in the wild has been confirmed so far.
What to do
Upgrade P4 Search to 2026.4.2. Patching alone is not sufficient for the default-token issue: because the token may be a known value, set a strong and unique service authentication token after the upgrade and rotate any credentials the service held.
In the meantime, confirm that neither the P4 Search service nor any JDWP debug port is reachable from untrusted networks, and restrict access to the hosts that legitimately need it. Review the service's access logs for authentication attempts that succeeded without an expected token value, and check whether the logging configuration or extension installer paths were modified.
Related CVEs
Sources
- Perforce Fixes Six P4 Search Vulnerabilities, Including a CVSS 10 Default Token Flaw — securityonline.info
- CVE-2026-100103 — THREATINT CVE kaydı
This story is based on the sources listed above. Always check the vendor’s official advisory before acting on critical systems.



