PERFORCE has released fixes for six vulnerabilities in P4 Search, all part of the 2026.4.2 release. The standout flaw, CVE-2026-100103, scores 10.0 on CVSSv4 and involves an authentication token that resets to a publicly documented default value in P4 Search container images, allowing an unauthenticated attacker to gain full control of the service.
Two other critical issues also affect container images: CVE-2026-100102 (CVSS 9.5) exposes an unauthenticated Java Debug Wire Protocol (JDWP) interface, enabling code execution as the P4 Search service account; CVE-2026-103510 (CVSS 9.5) is a blank-token fail-open bug that grants top privileges to unauthenticated attackers in affected configurations. In total, the article lists three critical flaws, with three additional lower-to-medium severity issues.
The remaining CVEs include CVE-2026-103507 (CVSS 7.5), which allows an attacker with the service token to write arbitrary files via the logging configuration, potentially leading to code execution; CVE-2026-103511 (CVSS 5.1) and CVE-2026-103512 (CVSS 5.3), which enable arbitrary file writes through the extension installer and host-based restriction bypass via spoofed client IP, respectively. Perforce notes that all six vulnerabilities affect versions up to 2026.4.1, with the fixes implemented in 2026.4.2.
While no exploitation in the wild has been confirmed, the guidance is clear: upgrade promptly, rotate the service token after upgrading, and keep P4 Search off the public internet. For container deployments, block the debug port or rebuild from patched images and audit P4 Server tickets for misuse.