Description
Perforce P4 Search container images prior to 2026.4.2 reset the service authentication token to a publicly documented default value. An unauthenticated attacker with network access can obtain the highest application privilege, potentially leading to arbitrary code execution and compromise of the connected P4 Server.
Published: 2026-10-05
Score: 10 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

Perforce P4 Search container images before version 2026.4.2 reset their service authentication token to a publicly documented default value. With this default token, an unauthenticated attacker can obtain the highest application privilege, enabling arbitrary code execution and full compromise of the connected P4 Server. The weakness is a default credential issue, allowing a privileged session to be started without authentication.

Affected Systems

The vulnerability affects Perfoce P4 (Helix Core) P4 Search container images released prior to 2026.4.2. No specific minor or patch sub‑versions are listed beyond the 2026.4.2 threshold, so all earlier releases are impacted. Users deploying earlier P4 Search containers should verify the image tag against the release date.

Risk and Exploitability

The CVSS score of 10 indicates maximum severity. EPSS data is not available, so exploitation probability cannot be quantified at present, but the lack of a requirement for privileged network positioning combined with the simplicity of the default token gives a high likelihood to attackers with network access. The vulnerability is not listed in the CISA KEV catalog. An attacker can exploit this by simply sending a request to the P4 Search service over the network, authenticating with the default token, and then performing privileged actions as the service administrator.

Generated by OpenCVE AI on October 5, 2026 at 10:51 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Deploy a P4 Search image with version 2026.4.2 or later, which removes the default authentication token behavior.
  • If an upgrade is not immediately possible, restrict network access to the P4 Search service so that only trusted hosts or internal networks can reach it, mitigating unauthorized external access.
  • Configure a firewall rule or reverse proxy to require valid authentication before allowing any requests to the P4 Search API, thereby preventing use of the default token.

Generated by OpenCVE AI on October 5, 2026 at 10:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 05 Oct 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 05 Oct 2026 09:00:00 +0000

Type Values Removed Values Added
Description Perforce P4 Search container images prior to 2026.4.2 reset the service authentication token to a publicly documented default value. An unauthenticated attacker with network access can obtain the highest application privilege, potentially leading to arbitrary code execution and compromise of the connected P4 Server.
Title Authentication bypass via default auth token in P4Search
Weaknesses CWE-1392
References
Metrics cvssV4_0

{'score': 10, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Perforce

Published:

Updated: 2026-10-05T13:56:57.748Z

Reserved: 2026-09-25T10:28:12.878Z

Link: CVE-2026-100103

cve-icon Vulnrichment

Updated: 2026-10-05T13:55:40.362Z

cve-icon NVD

Status : Received

Published: 2026-10-05T09:17:05.717

Modified: 2026-10-05T14:17:15.167

Link: CVE-2026-100103

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-05T11:00:17Z

Weaknesses