All CVEs
Vulnerability intelligence

CVE-2026-103511

Perforce P4 (Helix Core) CWE-73

Perforce P4 Search prior to 2026.4.2 does not validate file names supplied to its extension installation feature. An attacker with super-user or service-token privileges can write files with arbitrary content to the P4 Search installation directory.

CVSS Score
5.1
Medium
EPSS — Exploit Probability
—
Awaiting FIRST.org data · checked 2026-10-05
Exploitation
Not in CISA KEV
KEV does not include every exploited vulnerability
Remediation
unknown
Check vendor advisories
NVD entry PoC / advisory

1 article across 1 outlet · first covered Oct 5, 2026 · latest Oct 5, 2026

Coverage timeline

Related CVEs — Perforce