A CVSS 10 in Perforce P4 Search. The token was in the docs.
By Lior AharonovFounder, 7IT Solutions ·
On Monday, 5 October, CVE-2026-100103 was published with a CVSS 4.0 score of 10.0. Perforce P4 Search container images before 2026.4.2 reset the service authentication token to a publicly documented default value, letting an unauthenticated network attacker gain the highest privileges, potentially leading to code execution and P4 Server compromise.
If you run P4, it holds your source code. A search add-on that answers to a published token is a side door into it, and no login is needed. The token is public, and so is the race to patch.
If you run P4 Search from a container image, upgrade to 2026.4.2 or later today, block it from untrusted networks, and review P4 Server logs for admin activity you did not expect.
A default credential is a password you published to everyone. Including the people you hoped would never read the manual.
Lior Aharonov · my takeSources
- NVD: CVE-2026-100103 nvd.nist.gov
Researched with AI tools; every fact is checked against the linked sources.