Perforce P4 Search exposes unauthenticated JDWP debug interface enabling RCE
Perforce P4 Search containers before 2026.4.2 expose an unauthenticated Java debug interface, allowing any network-reachable attacker to execute arbitrary code as the P4 Search service.
- Vendor
- Perforce
- Product
- P4 Search (container images prior to 2026.4.2)
- CVSS
- 9.8
- EPSS (exploit probability)
- 0.4%
- Status
- patched
- Published
CVE-2026-100102 is a missing authentication control in Perforce P4 Search container images prior to version 2026.4.2. The containers expose a Java Debug Wire Protocol (JDWP) interface without requiring any authentication. JDWP allows a connected client to inspect and control a running Java process, including executing arbitrary bytecode; an attacker with network access to the interface can run code as the P4 Search service process.
The flaw is in how the container image is built and configured, not in P4 Search itself. JDWP is a standard developer debugging tool that should be disabled in production deployments.
Affected versions
- Perforce P4 Search container images prior to 2026.4.2
Fixed versions
- Perforce P4 Search 2026.4.2 and later
Remediation
Update P4 Search container images to version 2026.4.2. If patching immediately is not possible, block network access to the JDWP port at the host or cluster network level until the image can be updated. See the Perforce advisory and the NVD record for detailed remediation guidance.
