Perforce P4 Search container images prior to 2026.4.2 enable an unauthenticated Java debug interface. An attacker with network access to this interface can execute arbitrary code as the P4 Search service account, potentially leading to compromise of the connected P4 Server.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Mon, 05 Oct 2026 09:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Perforce P4 Search container images prior to 2026.4.2 enable an unauthenticated Java debug interface. An attacker with network access to this interface can execute arbitrary code as the P4 Search service account, potentially leading to compromise of the connected P4 Server. | |
| Title | RCE via exposed JDWP debug agent in P4Search | |
| Weaknesses | CWE-489 | |
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Perforce
Published:
Updated: 2026-10-05T08:32:32.241Z
Reserved: 2026-09-25T10:28:06.956Z
Link: CVE-2026-100102
No data.
Status : Received
Published: 2026-10-05T09:17:05.540
Modified: 2026-10-05T09:17:05.540
Link: CVE-2026-100102
No data.
OpenCVE Enrichment
Updated: 2026-10-05T10:45:21Z
Weaknesses