interesting · Edge — RCE
Pre-2026.4.2 P4 Search containers expose an unauthenticated debugger or highest application privilege.
Affects
Perforce P4 Search, a Windows/Linux search service connected to Helix Core/P4 Server and commonly deployed in containers.
A network peer can use unauthenticated JDWP for code execution as the service account, or obtain top application privilege through a documented default token or a fail-open blank token.
Detail and 5 sources
The product’s ordinary same-network placement makes those paths reachable to peers, but the affected service is specialized and fixed releases are available.
Sources
Researchhttps://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/100xxx/CVE-2026-100102.jsonResearchhttps://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/100xxx/CVE-2026-100103.jsonResearchhttps://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/103xxx/CVE-2026-103510.jsonResearchP4 Search configuration referenceResearchP4 Search: three CVEs and the 2026.4.2 fix — check tokens and debugging | Breachroad