在2026年4月2日之前的P4 Search版本中,当服务认证令牌为空时,其安全性验证未能正确失效。在受影响的配置中,具有网络访问权限的未授权攻击者可以获得最高级别的应用程序权限,这可能导致P4 Search及其连接的P4服务器被入侵。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Perforce | P4 (Helix Core) | 0 ~ 2026.4.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-100102 | 9.5 CRITICAL | RCE via exposed JDWP debug agent in P4Search |
| CVE-2026-103507 | 7.5 HIGH | Arbitrary file-write via log configuration path in P4Search |
| CVE-2026-103512 | 5.3 MEDIUM | Ticket host-binding bypass via spoofed client IP in P4Search |
| CVE-2026-103511 | 5.1 MEDIUM | Arbitrary file-write via extension installation in P4Search |
No comments yet