在 Perforce P4 Search 2026.4.2 版本之前,其日志配置接口未对写入的文件路径进行限制。攻击者若持有服务身份验证令牌,便可在主机上写入任意文件,从而可能以 P4 Search 服务账户的身份实现代码执行。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Perforce | P4 (Helix Core) | 0 ~ 2026.4.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-103510 | 9.5 CRITICAL | Authentication bypass via blank auth token in P4Search |
| CVE-2026-100102 | 9.5 CRITICAL | RCE via exposed JDWP debug agent in P4Search |
| CVE-2026-103512 | 5.3 MEDIUM | Ticket host-binding bypass via spoofed client IP in P4Search |
| CVE-2026-103511 | 5.1 MEDIUM | Arbitrary file-write via extension installation in P4Search |
No comments yet