7IT · News

A CVSS 10 in Perforce P4 Search. The token was in the docs.

By Lior AharonovFounder, 7IT Solutions ·

What happened

On Monday, 5 October, CVE-2026-100103 was published with a CVSS 4.0 score of 10.0. Perforce P4 Search container images before 2026.4.2 reset the service authentication token to a publicly documented default value, letting an unauthenticated network attacker gain the highest privileges, potentially leading to code execution and P4 Server compromise.

Why it matters

If you run P4, it holds your source code. A search add-on that answers to a published token is a side door into it, and no login is needed. The token is public, and so is the race to patch.

What to do

If you run P4 Search from a container image, upgrade to 2026.4.2 or later today, block it from untrusted networks, and review P4 Server logs for admin activity you did not expect.

A default credential is a password you published to everyone. Including the people you hoped would never read the manual.

Lior Aharonov · my take

Sources

securitycvedevopssource-control

Researched with AI tools; every fact is checked against the linked sources.

All 7IT news · Atom feed

Need a hand with something like this? Talk to 7IT.