Skip to content
feed: live
0dayNews
cloud

Perforce P4 Search Containers Expose RCE, Auth Bypass

Perforce P4 Search containers before 2026.4.2 expose an unauthenticated JDWP debug interface (RCE, CVSS 9.8) and reset auth tokens to a documented default (CVSS 9.1).

Perforce P4 Search Containers Expose RCE, Auth Bypass
Image: AI-generated — no human photographer / 0dayNews AI Cover · Generated on-site infrastructure — no external license
kilobaudDave "Kilobaud" Ferris·Published ·2 min read

Perforce has published advisories for two critical vulnerabilities in its P4 Search container images, both allowing unauthenticated attackers to access the service. Both are fixed in version 2026.4.2.

The first, CVE-2026-100102 (CVSS 9.8), is the more direct of the two. Container images prior to 2026.4.2 expose a Java Debug Wire Protocol (JDWP) debug interface without requiring authentication. JDWP is a mechanism that allows debuggers to attach to a running Java process and issue instructions to it; leaving it open in a deployed container is equivalent to leaving the service’s admin console network-accessible and unauthenticated. An attacker who can reach that port can execute arbitrary code as the P4 Search service.

The second, CVE-2026-100103 (CVSS 9.1), is the subtler problem. On startup, the container resets its service authentication token to a value documented in Perforce’s own public documentation. Any attacker who can reach the P4 Search API endpoint can look up that default token and authenticate as a legitimate service caller, bypassing access controls entirely.

What to do

Update P4 Search container images to 2026.4.2 immediately. For teams that cannot patch right away, restricting network access to the JDWP port is a partial mitigation for CVE-2026-100102. No equivalent workaround exists for CVE-2026-100103 short of regenerating the auth token after container startup, since the API endpoint itself cannot be blocked without disabling the service. Perforce’s advisories include exact remediation steps.

Why this comes up repeatedly

Both flaws follow patterns that recur in containerized enterprise software. Debug interfaces like JDWP are common in development container images, and they often survive into production through inattention rather than intent; a container image built for integration testing often differs from a production image only in its tag. Organizations running Perforce’s Helix suite should confirm which image variant is deployed and whether the JDWP port is exposed at the cluster or host firewall level.

Documented default credentials and tokens are a separate but similarly persistent problem. A vendor publishing its default token in documentation does not make exploitation unlikely; it makes the token findable in a fifteen-second search. The pattern shows up across enough products, enough years, and enough incident reports that the only reasonable response is to treat any documented default as publicly known and rotate it immediately.

Perforce P4 Search is a component of the company’s Helix suite, used primarily in enterprise software development and game studio environments for version control and asset management search. The NVD records for CVE-2026-100102 and CVE-2026-100103 are available for full technical detail.


Related coverage: Fleet MDM Auth Bypass Allows Rogue Device Enrollment, Dell CSM Critical Flaws Allow Root on Kubernetes Nodes, Rejetto HFS RCE Under Active Exploitation

Related CVEs
  • [ CRITICAL ]CVE-2026-100102Perforce P4 Search exposes unauthenticated JDWP debug interface enabling RCE
  • [ CRITICAL ]CVE-2026-100103Perforce P4 Search resets auth token to publicly documented default on startup

Found this useful? Share it.