Description
Perforce P4 Search container images prior to 2026.4.2 enable an unauthenticated Java debug interface. An attacker with network access to this interface can execute arbitrary code as the P4 Search service account, potentially leading to compromise of the connected P4 Server.
Published: 2026-10-05
Score: 9.5 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

The vulnerability allows the execution of arbitrary code through an exposed Java Debug Wire Protocol (JDWP) interface in Perforce P4 Search container images. Attackers with network access to this interface can run code as the service account, potentially compromising the connected P4 Server. This is a classic example of an unrestricted input flaw in a debugging interface, classified as CWE-489.

Affected Systems

Outdated Perforce P4 Search container images prior to version 2026.4.2 that enable the JDWP debug interface are affected. The affected systems are “Perforce P4 (Helix Core)” implementations running those older container images, regardless of the operating system environment.

Risk and Exploitability

The CVSS score of 9.5 indicates critical severity, and the lack of an EPSS score means that exploitation likelihood cannot be quantified from that metric alone. The vulnerability is exposed on the network and requires no authentication, making it a high‑risk local console attack for anyone with network access to the debug port. It is not currently listed in CISA’s KEV catalog, but the remote code execution potential warrants a high priority response.

Generated by OpenCVE AI on October 5, 2026 at 10:30 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to P4 Search version 2026.4.2 or later, which removes the exposed JDWP debug interface.
  • Disable or remove the JDWP debug agent from the container configuration to eliminate the attack surface.
  • Restrict network access to the JDWP port using firewall rules or container network policies so that only trusted management hosts can reach it.

Generated by OpenCVE AI on October 5, 2026 at 10:30 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 05 Oct 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 05 Oct 2026 09:00:00 +0000

Type Values Removed Values Added
Description Perforce P4 Search container images prior to 2026.4.2 enable an unauthenticated Java debug interface. An attacker with network access to this interface can execute arbitrary code as the P4 Search service account, potentially leading to compromise of the connected P4 Server.
Title RCE via exposed JDWP debug agent in P4Search
Weaknesses CWE-489
References
Metrics cvssV4_0

{'score': 9.5, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Perforce

Published:

Updated: 2026-10-05T13:14:31.402Z

Reserved: 2026-09-25T10:28:06.956Z

Link: CVE-2026-100102

cve-icon Vulnrichment

Updated: 2026-10-05T13:14:27.877Z

cve-icon NVD

Status : Received

Published: 2026-10-05T09:17:05.540

Modified: 2026-10-05T14:17:13.667

Link: CVE-2026-100102

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-05T10:45:21Z

Weaknesses