Perforce P4 Search prior to 2026.4.2 does not validate file names supplied to its extension installation feature. An attacker with super-user or service-token privileges can write files with arbitrary content to the P4 Search installation directory.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Mon, 05 Oct 2026 09:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Perforce P4 Search prior to 2026.4.2 does not validate file names supplied to its extension installation feature. An attacker with super-user or service-token privileges can write files with arbitrary content to the P4 Search installation directory. | |
| Title | Arbitrary file-write via extension installation in P4Search | |
| Weaknesses | CWE-73 | |
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Perforce
Published:
Updated: 2026-10-05T08:40:35.022Z
Reserved: 2026-09-30T17:38:12.196Z
Link: CVE-2026-103511
No data.
Status : Received
Published: 2026-10-05T09:17:07.113
Modified: 2026-10-05T09:17:07.113
Link: CVE-2026-103511
No data.
OpenCVE Enrichment
Updated: 2026-10-05T10:30:18Z
Weaknesses