CVE-2026-100103

LOWCVSS 10.0 · CRITICAL

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Perforce P4 Search container images prior to 2026.4.2 reset the service authentication token to a publicly documented default value. An unauthenticated attacker with network access can obtain the highest application privilege, potentially leading to arbitrary code execution and compromise of the connected P4 Server.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-1392

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • 2 total mentions across 1 day

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-10-05: 210-05
Referenced assets1 URL
By indicator
Full discourse2 posts
  • Daily CyberSecurity@Daily_CyberSec

    Perforce fixes six P4 Search vulnerabilities, including CVE-2026-100103 (CVSS 10) and a JDWP RCE flaw. Upgrade to 2026.4.2 now. #Perforce #P4Search #HelixCore #CVE2026100103 #CVE2026100102 #CVE2026103510 #DevSecOps #Vulnerability https://securityonline.info/perforce-p4-search-vulnerabilities/

    01000398
    13.0K followersView on X
  • Atlas Threat Monitoring@ThreatAtlas

    Unpatched vulnerabilities don't stay hidden on our atlas. #CVE CRITICAL VULNERABILITY DETECTED CVE ID → CVE-2026-100103 Vendor → Unknown Severity → Critical — CVSS 10.0 Product → Unknown Date → 2026-10-05 A critical vulnerability (Use of Default Credentials) has been disclosed affecting Unknown. Patch immediately. Powered by @Brandefense #ThreatIntel #CyberSecurity #CVE #Unknown

    0000060
    444 followersView on X

Explore more