在 Perforce P4 Search 2026.4.2 版本之前,其扩展安装功能未对用户提供的文件名进行验证。拥有超级用户或服务令牌权限的攻击者可以在 P4 Search 安装目录中写入任意内容的文件。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Perforce | P4 (Helix Core) | 0 ~ 2026.4.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-103510 | 9.5 CRITICAL | Authentication bypass via blank auth token in P4Search |
| CVE-2026-100102 | 9.5 CRITICAL | RCE via exposed JDWP debug agent in P4Search |
| CVE-2026-103507 | 7.5 HIGH | Arbitrary file-write via log configuration path in P4Search |
| CVE-2026-103512 | 5.3 MEDIUM | Ticket host-binding bypass via spoofed client IP in P4Search |
No comments yet