CVE-2026-100103: CWE-1392 Use of default credentials in Perfoce P4 (Helix Core)
Description
Perforce P4 Search container images prior to 2026.4.2 reset the service authentication token to a publicly documented default value. An unauthenticated attacker with network access can obtain the highest application privilege, potentially leading to arbitrary code execution and compromise of the connected P4 Server.
CVSS v4.0
Score 10.0critical
Affected software
Perfoce
P4 (Helix Core)
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-100103 describes a vulnerability in Perforce P4 (Helix Core) Search container images before version 2026.4.2, where the service authentication token is reset to a default value that is publicly documented. This flaw enables an unauthenticated attacker with network access to obtain the highest application privileges, which could lead to arbitrary code execution and compromise of the connected P4 Server. The vulnerability is classified under CWE-1392 (Use of default credentials).
Potential Impact
An unauthenticated attacker with network access can exploit this vulnerability to gain the highest application privileges on the Perforce P4 Server. This can result in arbitrary code execution and full compromise of the server, posing a critical security risk.
Mitigation Recommendations
A fix is available in Perforce P4 (Helix Core) version 2026.4.2. Users should upgrade to version 2026.4.2 or later to remediate this vulnerability. No other mitigation guidance is provided in the vendor advisory.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- Perforce
- Date Reserved
- 2026-09-25T10:28:12.878Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6ac368002cdf04f656e43ff8
Added to database: 10/05/2026, 09:04:00 UTC
Last enriched: 10/05/2026, 09:18:34 UTC
Last updated: 10/05/2026, 18:56:34 UTC
Views: 19
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.