CVE-2026-100103
Received Received - Intake

Perforce P4 Search Authentication Token Reset Vulnerability

Vulnerability report for CVE-2026-100103, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-05

Last updated on: 2026-10-05

Assigner: Perforce

Description

Perforce P4 Search container images prior to 2026.4.2 reset the service authentication token to a publicly documented default value. An unauthenticated attacker with network access can obtain the highest application privilege, potentially leading to arbitrary code execution and compromise of the connected P4 Server.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-05
Last Modified
2026-10-05
Generated
2026-10-05
AI Q&A
2026-10-05
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
perforce p4_search to 2026.4.2 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-1392 The product uses default credentials (such as passwords or cryptographic keys) for potentially critical functionality.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

Perforce P4 Search container images before 2026.4.2 reset the service authentication token to a publicly known default value. This allows unauthenticated attackers with network access to gain highest application privileges, potentially leading to arbitrary code execution and compromise of the connected P4 Server.

Impact Analysis

An attacker could exploit this to gain full control over the P4 Search service and connected P4 Server, potentially leading to data theft, unauthorized modifications, or system disruption. This could affect data integrity, confidentiality, and availability.

Compliance Impact

This vulnerability could lead to unauthorized access and data breaches, violating GDPR's data protection requirements and HIPAA's security rules. Organizations may face legal penalties, reputational damage, and loss of compliance certifications.

Mitigation Strategies

Upgrade Perforce P4 Search container images to version 2026.4.2 or later to ensure the authentication token is not reset to a default value. Verify the token has been changed from the default after upgrade.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-100103. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart