Impact
Perforce P4 Search versions prior to 2026.4.2 allow the logging configuration interface to write files without restricting the target path. An attacker who holds a valid service authentication token can instruct the service to write data to any file on the host, which can be used to deposit malicious code and later execute it as the P4 Search service account. The vulnerability is a classic path‑traversal or file‑write flaw and is classified as CWE‑73.
Affected Systems
The affected vendor is Perforce, product P4 (Helix Core). All releases before 2026.4.2 are impacted; the issue is triggered via the logging configuration functionality exposed by the service.
Risk and Exploitability
The CVSS score of 7.5 indicates a high severity. No EPSS score is available, and the vulnerability is not listed in the CISA KEV catalog. Because an attacker needs a valid service authentication token, the attack requires legitimate access to the service, making it an authenticated exploitation vector. Once an authenticated attacker gains the ability to write arbitrary files, they can impersonate the service account or drop executable payloads, potentially taking full control of the host system.
OpenCVE Enrichment