Vulnerability intelligence
CVE-2026-100103
Perforce P4 Search container images prior to 2026.4.2 reset the service authentication token to a publicly documented default value. An unauthenticated attacker with network access can obtain the highest application privilege, potentially leading to arbitrary code execution and compromise of the connected P4 Server.
CVSS Score
10
Critical
EPSS — Exploit Probability
—
Awaiting FIRST.org data · checked 2026-10-05
Exploitation
Not in CISA KEV
KEV does not include every exploited vulnerability
Remediation
unknown
Check vendor advisories
1 article across 1 outlet · first covered Oct 5, 2026 · latest Oct 5, 2026
Coverage timeline
-
Perforce P4 Search Flaws Let Attackers Seize Unprotected Servicessecurityonline.info · Oct 5, 2026