CVE-2026-100103: Perfoce p4 Helix Core

Critical severity, CVSS 10.0. EPSS: 0.4% chance of exploitation in the next 30 days.

Perforce P4 Search container images prior to 2026.4.2 reset the service authentication token to a publicly documented default value. An unauthenticated attacker with network access can obtain the highest application privilege, potentially leading to arbitrary code execution and compromise of the connected P4 Server.

Affected products

  • Perfoce p4 Helix Core: up to and including 2026.4.1

Published 2026-10-05. Last modified 2026-10-06.