Vulnerability intelligence
CVE-2026-103507
Perforce P4 Search prior to 2026.4.2 does not restrict file paths written through its logging configuration interface. An attacker holding the service authentication token can write arbitrary files on the host, potentially leading to code execution as the P4 Search service account.
CVSS Score
7.5
High
EPSS — Exploit Probability
—
Awaiting FIRST.org data · checked 2026-10-05
Exploitation
Not in CISA KEV
KEV does not include every exploited vulnerability
Remediation
unknown
Check vendor advisories
1 article across 1 outlet · first covered Oct 5, 2026 · latest Oct 5, 2026
Coverage timeline
-
Perforce P4 Search Flaws Let Attackers Seize Unprotected Servicessecurityonline.info · Oct 5, 2026