Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 05 Oct 2026 09:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Perforce P4 Search prior to 2026.4.2 does not validate file names supplied to its extension installation feature. An attacker with super-user or service-token privileges can write files with arbitrary content to the P4 Search installation directory. | |
| Title | Arbitrary file-write via extension installation in P4Search | |
| Weaknesses | CWE-73 | |
| References |
| |
| Metrics |
cvssV4_0
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: Perforce
Published:
Updated: 2026-10-05T08:40:35.022Z
Reserved: 2026-09-30T17:38:12.196Z
Link: CVE-2026-103511
No data.
Status : Received
Published: 2026-10-05T09:17:07.113
Modified: 2026-10-05T09:17:07.113
Link: CVE-2026-103511
No data.
OpenCVE Enrichment
Updated: 2026-10-05T10:30:18Z
-
CWE-73
External Control of File Name or Path