OCTOBER 6, 2026
Live Feed
Back to database
Case File

CVE-2026-100102

CRITICAL · CVSS 9.5 EPSS 0.36%

Source: NVD + CISA KEV + EPSS · Published 2026-10-05 · Last synced 2026-10-06

CyberRota Analysis

AI-Generated

The vulnerability affects Perforce P4 Search container images prior to version 2026.4.2, which expose an unauthenticated Java debug interface. An attacker with network access can exploit this interface to execute arbitrary code as the P4 Search service account, potentially compromising the connected P4 Server. Organizations using these affected versions should prioritize patching to mitigate the risk of unauthorized access and potential data breaches.

CVE
CVE-2026-100102
Severity
CRITICAL
CVSS
9.5
EPSS
0.36%
Java

Original NVD Description

Perforce P4 Search container images prior to 2026.4.2 enable an unauthenticated Java debug interface. An attacker with network access to this interface can execute arbitrary code as the P4 Search service account, potentially leading to compromise of the connected P4 Server.