Impact
The vulnerability allows the execution of arbitrary code through an exposed Java Debug Wire Protocol (JDWP) interface in Perforce P4 Search container images. Attackers with network access to this interface can run code as the service account, potentially compromising the connected P4 Server. This is a classic example of an unrestricted input flaw in a debugging interface, classified as CWE-489.
Affected Systems
Outdated Perforce P4 Search container images prior to version 2026.4.2 that enable the JDWP debug interface are affected. The affected systems are “Perforce P4 (Helix Core)” implementations running those older container images, regardless of the operating system environment.
Risk and Exploitability
The CVSS score of 9.5 indicates critical severity, and the lack of an EPSS score means that exploitation likelihood cannot be quantified from that metric alone. The vulnerability is exposed on the network and requires no authentication, making it a high‑risk local console attack for anyone with network access to the debug port. It is not currently listed in CISA’s KEV catalog, but the remote code execution potential warrants a high priority response.
OpenCVE Enrichment