Unauthenticated Java Debug Interface Vulnerability in Perforce P4 Search
CVE-2026-100102

9.5CRITICAL

Key Information:

Vendor

Perforce

Vendor
CVE Published:
5 October 2026

What is CVE-2026-100102?

The Perforce P4 Search container images before version 2026.4.2 are susceptible to a vulnerability that exposes an unauthenticated Java debug interface. This flaw allows an attacker with network access to exploit the interface, enabling the execution of arbitrary code under the privileges of the P4 Search service account. This access can potentially compromise the security and integrity of the connected P4 Server, raising concerns about data loss and unauthorized access.

Affected Version(s)

P4 (Helix Core) 0 <= 2026.4.1

P4 (Helix Core) 0 <= 2026.4.1

P4 (Helix Core) 2026.4.2

References

CVSS V4

Score:
9.5
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.