External risk intelligence

Perforce P4 Search Authentication Bypass Via Default Token

CVE advisorySeverity: CRITICAL (CVSS 10.0)

CVE-2026-100103

Perforce P4 Search is a specialized component used within development environments to index and search code repositories. While it requires network access, it is typically deployed within internal development infrastructure or protected by network controls, making direct public internet exposure uncommon compared to edge services or gateways.

Halo Surface Signal: 3 out of 5 — possibly public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This advisory concerns a vulnerability in Perforce P4 Search container images where the service authentication token could be reset to a default value. An unauthenticated attacker with network access could exploit this to gain the highest application privilege, potentially leading to code execution and compromise of connected P4 Servers.

  • A default token could grant broad system access.
  • This impacts code search tools critical for development.
  • Confirm if your Perforce P4 Search deployment is affected.

Attack Path

How an attacker could exploit the issue

An attacker with network access could target the Perforce P4 Search container, which may be exposed externally. By exploiting a flaw that resets the authentication token to a default value, an unauthenticated attacker can gain the highest privileges within the application. This elevated access could potentially allow for arbitrary code execution and compromise of connected Perforce servers.

  • Network access required.
  • Resets authentication token to default.
  • Highest application privilege achieved.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow an unauthenticated attacker with network access to gain the highest application privileges. This elevated access may lead to the execution of arbitrary code and compromise of the connected P4 Server.

  • P4 Search service and connected P4 Server.
  • Network access allows default token exposure.
  • Potential for code execution and server compromise.

Operational Fix

Recommended remediation, mitigation, and detection steps

The Perforce P4 Search container image vulnerability requires action from teams responsible for application security and infrastructure management. The initial focus should be on identifying all deployments of the affected Perforce P4 Search container, assessing their network reachability and business criticality, and then confirming the accountable system owner. Remediation planning should follow, prioritizing based on the identified risk.

  • Identify affected Perforce P4 Search deployments.
  • Verify network exposure and business criticality.
  • Plan targeted remediation or risk reduction.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Perforce P4 Search?

Perforce P4 Search is a specialized tool integrated into development environments. It indexes and makes code repositories searchable for teams using the Perforce version control ecosystem. Because it manages significant amounts of proprietary source code data, it serves as a critical component for developers to navigate large-scale software projects efficiently.

What does CVE-2026-100103 mean?

This vulnerability, classified as CWE-1392, involves the use of a hardcoded or default authentication token within affected container images. Essentially, the software can reset its secret handshake to a publicly known value. An attacker can use this known value to bypass login mechanisms entirely, granting them full administrative control over the P4 Search instance.

How can someone trigger this CVE?

An attacker needs network access to the P4 Search service to exploit this. The flaw is triggered when the authentication token resets to the default value. It is important to note that this does not require a user to perform any specific action or click a link; it is a structural weakness in the application's authentication logic that exists regardless of user behavior.

Do I need to worry if my P4 Search is internal?

Yes, but your urgency may vary. According to Halo Surface Signal, P4 Search is usually found in internal development infrastructure rather than on the public internet. While this offers some protection, an attacker who has already breached another part of your internal network could still reach and exploit this service, meaning it remains a risk for your local environment.

What should I do to secure my environment?

Start by auditing your infrastructure to locate every instance of the P4 Search container. Once identified, evaluate which deployments are reachable over your network and determine who is responsible for managing them. Prioritize these systems based on the sensitivity of the code they index, and prepare for an update to move away from the vulnerable container images.

References