CVE-2026-103507 PUBLISHED

Arbitrary file-write via log configuration path in P4Search

Assigner: Perforce
Reserved: 30.09.2026 Published: 05.10.2026 Updated: 05.10.2026

Perforce P4 Search prior to 2026.4.2 does not restrict file paths written through its logging configuration interface. An attacker holding the service authentication token can write arbitrary files on the host, potentially leading to code execution as the P4 Search service account.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CVSS Score: 7.5

Product Status

Vendor Perforce
Product P4 (Helix Core)
Versions Default: affected
  • affected from 0 to 2026.4.1 (incl.)
  • Version 2026.4.2 is unaffected

Credits

  • Khoa Bui (https://github.com/zenniskayy2k4) finder

References

Problem Types

  • CWE-73 External control of file name or path CWE