CVE-2026-103507
Received Received - Intake

Path Traversal in Perforce P4 Search

Vulnerability report for CVE-2026-103507, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-05

Last updated on: 2026-10-05

Assigner: Perforce

Description

Perforce P4 Search prior to 2026.4.2 does not restrict file paths written through its logging configuration interface. An attacker holding the service authentication token can write arbitrary files on the host, potentially leading to code execution as the P4 Search service account.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-05
Last Modified
2026-10-05
Generated
2026-10-05
AI Q&A
2026-10-05
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
perforce p4_search to 2026.4.2 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-73 The product allows user input to control or influence paths or file names that are used in filesystem operations.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

Perforce P4 Search before version 2026.4.2 has a flaw where file paths are not properly restricted in its logging configuration interface. An attacker with the service authentication token can exploit this to write arbitrary files on the host system. This could allow the attacker to execute code with the permissions of the P4 Search service account.

Impact Analysis

If you use Perforce P4 Search prior to 2026.4.2, an attacker who gains access to the service authentication token could write malicious files to your system. This may lead to full compromise of the P4 Search service account, allowing the attacker to execute arbitrary code on your host.

Mitigation Strategies

Upgrade Perforce P4 Search to version 2026.4.2 or later to address the file path restriction issue. Ensure the service authentication token is not exposed and restrict access to authenticated users only.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-103507. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart