CVE-2026-100102 PUBLISHED

RCE via exposed JDWP debug agent in P4Search

Assigner: Perforce
Reserved: 25.09.2026 Published: 05.10.2026 Updated: 05.10.2026

Perforce P4 Search container images prior to 2026.4.2 enable an unauthenticated Java debug interface. An attacker with network access to this interface can execute arbitrary code as the P4 Search service account, potentially leading to compromise of the connected P4 Server.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
CVSS Score: 9.5

Product Status

Vendor Perforce
Product P4 (Helix Core)
Versions Default: affected
  • affected from 0 to 2026.4.1 (incl.)
  • Version 2026.4.2 is unaffected

References

Problem Types

  • CWE-489 Active debug code CWE