CVE-2026-103511
Arbitrary file-write via extension installation in P4Search
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
Perforce P4 Search prior to 2026.4.2 does not validate file names supplied to its extension installation feature. An attacker with super-user or service-token privileges can write files with arbitrary content to the P4 Search installation directory.
| CWE | CWE-73 |
| Vendor | perforce |
| Product | p4 (helix core) |
| Published | Oct 5, 2026 |
Stay Ahead of the Next One
Get instant alerts for perforce p4 (helix core)
Be the first to know when new unknown vulnerabilities affecting perforce p4 (helix core) are published — delivered to Slack, Telegram or Discord.
Get Free Alerts →
Free · No credit card · 60 sec setup
Affected Versions
Perforce / P4 (Helix Core)
0 ≤ 2026.4.1
References
Credits
Khoa Bui (https://github.com/zenniskayy2k4)