CVE-2026-103511: Perforce p4 Helix Core
Medium severity, CVSS 5.1. EPSS: 0.3% chance of exploitation in the next 30 days.
Perforce P4 Search prior to 2026.4.2 does not validate file names supplied to its extension installation feature. An attacker with super-user or service-token privileges can write files with arbitrary content to the P4 Search installation directory.
Affected products
- Perforce p4 Helix Core: up to and including 2026.4.1
Published 2026-10-05. Last modified 2026-10-06.