Arbitrary File Write Vulnerability in Perforce P4 Search
CVE-2026-103507

7.5HIGH

Key Information:

Vendor

Perforce

Vendor
CVE Published:
5 October 2026

What is CVE-2026-103507?

An arbitrary file write vulnerability exists in Perforce P4 Search before version 2026.4.2, allowing an attacker with the service authentication token to manipulate the logging configuration interface. This flaw enables unauthorized file writing on the host system, posing significant security risks by potentially facilitating code execution under the privileges of the P4 Search service account. Proper handling and restrictions on file paths in the logging configuration are critical to preventing exploitation.

Affected Version(s)

P4 (Helix Core) 0 <= 2026.4.1

P4 (Helix Core) 0 <= 2026.4.1

P4 (Helix Core) 2026.4.2

References

CVSS V4

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Khoa Bui (https://github.com/zenniskayy2k4)
.