TL;DR
Perforce has patched six P4 Search vulnerabilities in version 2026.4.2. The worst, CVE-2026-100103, scores a perfect 10.0 on CVSS 4.0 and lets an unauthenticated attacker take full control of the service. Three of the six flaws are critical, and each can lead to compromise of the connected P4 Server.
- Total: 6 CVEs
- Severity: 3 Critical · 1 High · 2 Medium
- Actively exploited: None confirmed
- Highest severity: 10.0 (Critical · CVSSv4) — CVE-2026-100103
- Action: Apply the latest security updates now
Turn matching CVEs into GitHub Issues automatically — no copy-pasting, no duplicates.
Try Team free for 14 daysNotable CVEs
| CVE | CVSS (CVSSv4) | Type | Fixed in | Status |
|---|---|---|---|---|
| CVE-2026-100103 | 10 | Authentication bypass via default auth token in P4Search | 2026.4.2 | Not exploited |
| CVE-2026-100102 | 9.5 | RCE via exposed JDWP debug agent in P4Search | 2026.4.2 | Not exploited |
| CVE-2026-103510 | 9.5 | Authentication bypass via blank auth token in P4Search | 2026.4.2 | Not exploited |
| CVE-2026-103507 | 7.5 | Arbitrary file-write via log configuration path in P4Search | 2026.4.2 | Not exploited |
| CVE-2026-103512 | 5.3 | Ticket host-binding bypass via spoofed client IP in P4Search | 2026.4.2 | Not exploited |
| CVE-2026-103511 | 5.1 | Arbitrary file-write via extension installation in P4Search | 2026.4.2 | Not exploited |
Why It Matters
P4 Search is the search service for Perforce P4, formerly Helix Core. Game studios and large engineering teams use P4 Server to store source code and assets. Therefore, a hijacked search service gives attackers a path into the code repository itself.
So far, no exploitation in the wild or public proof-of-concept has been confirmed. Researcher Khoa Bui is credited with finding five of the six flaws.
How the Attacks Work
Critical Flaws
CVE-2026-100103 (CVSS 10.0) affects P4 Search container images. They “reset the service authentication token to a publicly documented default value,” Perforce says. As a result, anyone with network access can gain the highest application privilege.
Next, CVE-2026-100102 (CVSS 9.5) also hits the container images. They expose an unauthenticated Java debug (JDWP) interface. An attacker who reaches it can run arbitrary code as the P4 Search service account.
Meanwhile, CVE-2026-103510 (CVSS 9.5) is a fail-open bug. When the service token is blank, P4 Search grants top privileges to unauthenticated attackers in affected configurations.
High and Medium Flaws
CVE-2026-103507 (CVSS 7.5) lets a holder of the service token write arbitrary files through the logging configuration. That could lead to code execution. Similarly, CVE-2026-103511 (CVSS 5.1) allows file writes through the extension installer. Finally, CVE-2026-103512 (CVSS 5.3) lets an attacker with a stolen P4 Server ticket bypass host-based restrictions by spoofing a client address.
Affected Versions
All six P4 Search vulnerabilities affect versions 2026.4.1 and earlier. The two most severe bugs apply to the official container images.
Patch and Mitigation Steps
Upgrade P4 Search to 2026.4.2 right away. Perforce details each fix in its advisories for the default auth token bypass, the exposed JDWP debug agent, and the blank auth token bypass.
In addition, set a strong, unique service token and keep P4 Search off the public internet. Container users should block the debug port and rebuild from the patched image. After upgrading, rotate the service token and review P4 Server tickets for misuse.
Support Our Threat Intelligence
Find our vulnerability reports and weekly recaps helpful? Support our work today and unlock a 100% ad-free reading experience!