Authentication Bypass in Perforce P4 Search Container Images
CVE-2026-100103

10CRITICAL

Key Information:

Vendor

Perfoce

Vendor
CVE Published:
5 October 2026

What is CVE-2026-100103?

The Perforce P4 Search container images prior to version 2026.4.2 have a significant vulnerability where the service authentication token is reset to a publicly known default value. This flaw allows an unauthenticated attacker with network access to gain the highest level of application privilege. Such unauthorized access can lead to arbitrary code execution, posing a serious threat to the integrity and security of the connected P4 Server.

Affected Version(s)

P4 (Helix Core) 0 <= 2026.4.1

P4 (Helix Core) 0 <= 2026.4.1

P4 (Helix Core) 2026.4.2

References

CVSS V4

Score:
10
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Khoa Bui (https://github.com/zenniskayy2k4)
.