Perforce P4 Search resets auth token to publicly documented default on startup
Perforce P4 Search containers before 2026.4.2 reset the service authentication token to a publicly documented default value, letting unauthenticated attackers authenticate as a legitimate service caller.
- Vendor
- Perforce
- Product
- P4 Search (container images prior to 2026.4.2)
- CVSS
- 9.1
- EPSS (exploit probability)
- 0.4%
- Status
- patched
- Published
CVE-2026-100103 is an authentication bypass in Perforce P4 Search container images prior to version 2026.4.2. On container startup, the image resets the service authentication token to a value published in Perforce’s own documentation. Any attacker who can reach the P4 Search API endpoint can use that documented token to authenticate as a service-level caller.
Unlike CVE-2026-100102 (the co-disclosed RCE via exposed JDWP), there is no effective network-level workaround for this flaw: the P4 Search API endpoint is the service, and blocking access to it defeats the purpose of the deployment. Updating to the patched image is the only reliable fix.
Affected versions
- Perforce P4 Search container images prior to 2026.4.2
Fixed versions
- Perforce P4 Search 2026.4.2 and later
Remediation
Update P4 Search container images to version 2026.4.2 immediately. After updating, verify the container does not retain the default token from a prior startup. See the Perforce advisory and the NVD record for detailed remediation guidance.
