Skip to content
feed: live
0dayNews
CVE Record
[ CRITICAL ]CVE-2026-100103

Perforce P4 Search resets auth token to publicly documented default on startup

Perforce P4 Search containers before 2026.4.2 reset the service authentication token to a publicly documented default value, letting unauthenticated attackers authenticate as a legitimate service caller.

Vendor
Perforce
Product
P4 Search (container images prior to 2026.4.2)
CVSS
9.1
EPSS (exploit probability)
0.4%
Status
patched
Published

CVE-2026-100103 is an authentication bypass in Perforce P4 Search container images prior to version 2026.4.2. On container startup, the image resets the service authentication token to a value published in Perforce’s own documentation. Any attacker who can reach the P4 Search API endpoint can use that documented token to authenticate as a service-level caller.

Unlike CVE-2026-100102 (the co-disclosed RCE via exposed JDWP), there is no effective network-level workaround for this flaw: the P4 Search API endpoint is the service, and blocking access to it defeats the purpose of the deployment. Updating to the patched image is the only reliable fix.

Affected versions

  • Perforce P4 Search container images prior to 2026.4.2

Fixed versions

  • Perforce P4 Search 2026.4.2 and later

Remediation

Update P4 Search container images to version 2026.4.2 immediately. After updating, verify the container does not retain the default token from a prior startup. See the Perforce advisory and the NVD record for detailed remediation guidance.