在 Perforce P4 Search 2026.4.2 版本之前,系统在验证某些身份认证请求时,会信任客户端提供的地址。攻击者如果持有一个被盗的 P4 服务器凭证(ticket),可以绕过基于主机的凭证限制以及受信任地址控制机制,从而以该凭证所有者的身份访问 P4 Search。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Perforce | P4 (Helix Core) | 0 ~ 2026.4.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-103510 | 9.5 CRITICAL | Authentication bypass via blank auth token in P4Search |
| CVE-2026-100102 | 9.5 CRITICAL | RCE via exposed JDWP debug agent in P4Search |
| CVE-2026-103507 | 7.5 HIGH | Arbitrary file-write via log configuration path in P4Search |
| CVE-2026-103511 | 5.1 MEDIUM | Arbitrary file-write via extension installation in P4Search |
No comments yet