Impact
The flaw arises because Perforce P4 Search extension installation does not validate the file names supplied by the installer. As a result, an attacker who can exercise super‑user or service‑token privileges can write files with arbitrary content into the P4 Search installation directory. This can allow modification of configuration files, binaries, or other files critical to the server’s operation and is an instance of input handling weakness (CWE‑73).
Affected Systems
Perforce Helix Core P4 Search versions earlier than 2026.4.2 are affected.
Risk and Exploitability
The CVSS score of 5.1 reflects a moderate severity for the vulnerability. The EPSS score is not available and the issue is not cataloged in the CISA KEV list. Exploitation requires local access to a system that holds super‑user or service‑token privileges, which permits installation of extensions. Once an attacker can install an extension, they can use the flaw to write files in the installation directory, potentially compromising availability or leading to further privilege escalation if configuration files are altered.
OpenCVE Enrichment