Impact
Perforce P4 Search container images before version 2026.4.2 reset their service authentication token to a publicly documented default value. With this default token, an unauthenticated attacker can obtain the highest application privilege, enabling arbitrary code execution and full compromise of the connected P4 Server. The weakness is a default credential issue, allowing a privileged session to be started without authentication.
Affected Systems
The vulnerability affects Perfoce P4 (Helix Core) P4 Search container images released prior to 2026.4.2. No specific minor or patch sub‑versions are listed beyond the 2026.4.2 threshold, so all earlier releases are impacted. Users deploying earlier P4 Search containers should verify the image tag against the release date.
Risk and Exploitability
The CVSS score of 10 indicates maximum severity. EPSS data is not available, so exploitation probability cannot be quantified at present, but the lack of a requirement for privileged network positioning combined with the simplicity of the default token gives a high likelihood to attackers with network access. The vulnerability is not listed in the CISA KEV catalog. An attacker can exploit this by simply sending a request to the P4 Search service over the network, authenticating with the default token, and then performing privileged actions as the service administrator.
OpenCVE Enrichment