PT-2026-104752 · Perforce · P4 Search

·

CVE-2026-100103

·

Published

2026-10-05

·

Updated

2026-10-05

CVSS v4.0

10

Critical

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
Name of the Vulnerable Software and Affected Versions Perforce P4 Search versions prior to 2026.4.2
Description Container images reset the service authentication token to a publicly documented default value. An unauthenticated attacker with network access can use this to obtain the highest application privilege, which may lead to arbitrary code execution and compromise of the connected P4 Server.
Recommendations Upgrade to version 2026.4.2.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-100103

Affected Products

P4 Search