Description
Perforce P4 Search prior to 2026.4.2 does not validate file names supplied to its extension installation feature. An attacker with super-user or service-token privileges can write files with arbitrary content to the P4 Search installation directory.
Published: 2026-10-05
Score: 5.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Arbitrary file write
Action: Apply Patch
AI Analysis

Impact

The flaw arises because Perforce P4 Search extension installation does not validate the file names supplied by the installer. As a result, an attacker who can exercise super‑user or service‑token privileges can write files with arbitrary content into the P4 Search installation directory. This can allow modification of configuration files, binaries, or other files critical to the server’s operation and is an instance of input handling weakness (CWE‑73).

Affected Systems

Perforce Helix Core P4 Search versions earlier than 2026.4.2 are affected.

Risk and Exploitability

The CVSS score of 5.1 reflects a moderate severity for the vulnerability. The EPSS score is not available and the issue is not cataloged in the CISA KEV list. Exploitation requires local access to a system that holds super‑user or service‑token privileges, which permits installation of extensions. Once an attacker can install an extension, they can use the flaw to write files in the installation directory, potentially compromising availability or leading to further privilege escalation if configuration files are altered.

Generated by OpenCVE AI on October 5, 2026 at 10:27 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Perforce Helix Core P4 Search to version 2026.4.2 or later which implements proper file‑name validation for extension installation.
  • Configure the service to deny extension installation for accounts that do not require it, thereby reducing the attack surface for super‑user or service‑token holders.
  • Enforce strict file‑system permissions on the P4 Search installation directory so that only the responsible service account may write, limiting the impact if the flaw is exploited.

Generated by OpenCVE AI on October 5, 2026 at 10:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 05 Oct 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 05 Oct 2026 09:00:00 +0000

Type Values Removed Values Added
Description Perforce P4 Search prior to 2026.4.2 does not validate file names supplied to its extension installation feature. An attacker with super-user or service-token privileges can write files with arbitrary content to the P4 Search installation directory.
Title Arbitrary file-write via extension installation in P4Search
Weaknesses CWE-73
References
Metrics cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Perforce

Published:

Updated: 2026-10-05T12:29:55.650Z

Reserved: 2026-09-30T17:38:12.196Z

Link: CVE-2026-103511

cve-icon Vulnrichment

Updated: 2026-10-05T12:29:49.300Z

cve-icon NVD

Status : Received

Published: 2026-10-05T09:17:07.113

Modified: 2026-10-05T13:16:50.867

Link: CVE-2026-103511

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-05T10:30:18Z

Weaknesses
  • CWE-73

    External Control of File Name or Path