FR
live
tag

#helix-core

Perforce patches three critical flaws that open P4 Search without authentication

On 5 October 2026 Perforce published three critical CVEs in P4 Search, the containerised search engine for Helix Core: a hardcoded authentication token (CVSS 10) and an exposed JDWP debug interface let an unauthenticated network attacker run code right next to the source repository. The fix is a single container-image update to 2026.4.2 plus strict network isolation.

Type at least two characters.

↑ ↓ navigate ↵ open esc dismiss