EUVD Vulnerability Catalog

EUVD-2026-92295

Severity: CRITICAL Base Score: 9.5 CVSS Version: 4.0

Vulnerability Description

Perforce P4 Search container images prior to 2026.4.2 enable an unauthenticated Java debug interface. An attacker with network access to this interface can execute arbitrary code as the P4 Search service account, potentially leading to compromise of the connected P4 Server.

CVSS Vector Analysis

Below is the complete, human-readable breakdown of the CVSS metric string: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H

▪ Attack Vector (AV): Network
▪ Attack Complexity (AC): Low
▪ Attack Requirements (AT): Present
▪ Privileges Required (PR): None
▪ User Interaction (UI): None
▪ Vulnerability Confidentiality Impact (VC): High
▪ Vulnerability Integrity Impact (VI): High
▪ Vulnerability Availability Impact (VA): High
▪ Subsequent Confidentiality Impact (SC): High
▪ Subsequent Integrity Impact (SI): High
▪ Subsequent Availability Impact (SA): High

Affected Vendors & Systems

Vendor Perforce

References & Advisory Links

Metadata Profile

Database Authority

European Union Agency for Cybersecurity (ENISA) EUVD

Assigner

Perforce

EPSS Probability

0

Known Aliases
GHSA-9p2m-pch8-59mp CVE-2026-100102
Published On

2026-10-05

Last Updated

2026-10-05