Skip to finding
interesting · Edge — RCE

Pre-2026.4.2 P4 Search containers expose an unauthenticated debugger or highest application privilege.

Affects

Perforce P4 Search, a Windows/Linux search service connected to Helix Core/P4 Server and commonly deployed in containers.

A network peer can use unauthenticated JDWP for code execution as the service account, or obtain top application privilege through a documented default token or a fail-open blank token.

Detail and 5 sources
Share this finding
Get it by email

The same brief, every morning. One email a day, nothing else.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Tuesday, October 6, 2026