CVE-2026-100103 PUBLISHED

Authentication bypass via default auth token in P4Search

Assigner: Perforce
Reserved: 25.09.2026 Published: 05.10.2026 Updated: 05.10.2026

Perforce P4 Search container images prior to 2026.4.2 reset the service authentication token to a publicly documented default value. An unauthenticated attacker with network access can obtain the highest application privilege, potentially leading to arbitrary code execution and compromise of the connected P4 Server.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
CVSS Score: 10

Product Status

Vendor Perfoce
Product P4 (Helix Core)
Versions Default: affected
  • affected from 0 to 2026.4.1 (incl.)
  • Version 2026.4.2 is unaffected

Credits

  • Khoa Bui (https://github.com/zenniskayy2k4) finder

References

Problem Types

  • CWE-1392 Use of default credentials CWE