Authentication Bypass in Perforce P4 Search Container Images
CVE-2026-100103
10CRITICAL
What is CVE-2026-100103?
The Perforce P4 Search container images prior to version 2026.4.2 have a significant vulnerability where the service authentication token is reset to a publicly known default value. This flaw allows an unauthenticated attacker with network access to gain the highest level of application privilege. Such unauthorized access can lead to arbitrary code execution, posing a serious threat to the integrity and security of the connected P4 Server.
Affected Version(s)
P4 (Helix Core) 0 <= 2026.4.1
P4 (Helix Core) 0 <= 2026.4.1
P4 (Helix Core) 2026.4.2
References
CVSS V4
Score:
10
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Khoa Bui (https://github.com/zenniskayy2k4)
