Description
Perforce P4 Search prior to 2026.4.2 does not restrict file paths written through its logging configuration interface. An attacker holding the service authentication token can write arbitrary files on the host, potentially leading to code execution as the P4 Search service account.
Published: 2026-10-05
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Arbitrary file write enabling potential code execution
Action: Patch immediately
AI Analysis

Impact

Perforce P4 Search versions prior to 2026.4.2 allow the logging configuration interface to write files without restricting the target path. An attacker who holds a valid service authentication token can instruct the service to write data to any file on the host, which can be used to deposit malicious code and later execute it as the P4 Search service account. The vulnerability is a classic path‑traversal or file‑write flaw and is classified as CWE‑73.

Affected Systems

The affected vendor is Perforce, product P4 (Helix Core). All releases before 2026.4.2 are impacted; the issue is triggered via the logging configuration functionality exposed by the service.

Risk and Exploitability

The CVSS score of 7.5 indicates a high severity. No EPSS score is available, and the vulnerability is not listed in the CISA KEV catalog. Because an attacker needs a valid service authentication token, the attack requires legitimate access to the service, making it an authenticated exploitation vector. Once an authenticated attacker gains the ability to write arbitrary files, they can impersonate the service account or drop executable payloads, potentially taking full control of the host system.

Generated by OpenCVE AI on October 5, 2026 at 10:29 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update Perforce P4 Search to version 2026.4.2 or later to remove the unrestricted file write path
  • Revoke or limit the scope of service authentication tokens so that only trusted accounts can configure logging
  • Implement monitoring of log configuration changes or file writes that are outside expected directories to detect misuse

Generated by OpenCVE AI on October 5, 2026 at 10:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 05 Oct 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 05 Oct 2026 09:00:00 +0000

Type Values Removed Values Added
Description Perforce P4 Search prior to 2026.4.2 does not restrict file paths written through its logging configuration interface. An attacker holding the service authentication token can write arbitrary files on the host, potentially leading to code execution as the P4 Search service account.
Title Arbitrary file-write via log configuration path in P4Search
Weaknesses CWE-73
References
Metrics cvssV4_0

{'score': 7.5, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Perforce

Published:

Updated: 2026-10-05T13:38:51.831Z

Reserved: 2026-09-30T17:38:12.196Z

Link: CVE-2026-103507

cve-icon Vulnrichment

Updated: 2026-10-05T13:30:24.927Z

cve-icon NVD

Status : Received

Published: 2026-10-05T09:17:06.843

Modified: 2026-10-05T14:17:15.590

Link: CVE-2026-103507

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-05T10:30:18Z

Weaknesses
  • CWE-73

    External Control of File Name or Path