Arbitrary File Write Vulnerability in Perforce P4 Search
CVE-2026-103507
7.5HIGH
What is CVE-2026-103507?
An arbitrary file write vulnerability exists in Perforce P4 Search before version 2026.4.2, allowing an attacker with the service authentication token to manipulate the logging configuration interface. This flaw enables unauthorized file writing on the host system, posing significant security risks by potentially facilitating code execution under the privileges of the P4 Search service account. Proper handling and restrictions on file paths in the logging configuration are critical to preventing exploitation.
Affected Version(s)
P4 (Helix Core) 0 <= 2026.4.1
P4 (Helix Core) 0 <= 2026.4.1
P4 (Helix Core) 2026.4.2
References
CVSS V4
Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Khoa Bui (https://github.com/zenniskayy2k4)
