Perforce P4 Search 在版本 2026.4.2 之前的容器镜像启用了未经身份验证的 Java 调试接口。具备网络访问权限的攻击者可以利用该接口,以 P4 Search 服务账户的身份执行任意代码,可能导致与其连接的 P4 Server 被入侵。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Perforce | P4 (Helix Core) | 0 ~ 2026.4.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-103510 | 9.5 CRITICAL | Authentication bypass via blank auth token in P4Search |
| CVE-2026-103507 | 7.5 HIGH | Arbitrary file-write via log configuration path in P4Search |
| CVE-2026-103512 | 5.3 MEDIUM | Ticket host-binding bypass via spoofed client IP in P4Search |
| CVE-2026-103511 | 5.1 MEDIUM | Arbitrary file-write via extension installation in P4Search |
No comments yet