PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-103507 Perforce CVE debrief

CVE-2026-103507 is a high-severity vulnerability in Perforce P4 Search that allows an attacker with the service authentication token to write arbitrary files on the host, potentially leading to code execution. Defenders should assess exposure and prioritize mitigation. The vulnerability exists in versions prior to 2026.4.2 and is related to the logging configuration interface. Affected deployments should be identified, and owners assigned for follow-up. Official CVE and NVD records provide further details.

Vendor
Perforce
Product
P4 (Helix Core)
CVSS
HIGH 7.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-05
Original CVE updated
2026-10-05
Advisory published
2026-10-05
Advisory updated
2026-10-05

Who should care

Defenders responsible for Perforce P4 Search instances, as well as operators, platform administrators, vulnerability management teams, and security teams, should assess exposure and prioritize mitigation. They should verify instance versions, apply patches if necessary, and restrict access to the logging configuration interface. Additionally, they should monitor for suspicious file writes on the host and review compensating controls for exposed systems.

Why it matters

CVE-2026-103507 is a high-severity vulnerability in Perforce P4 Search that allows an attacker with the service authentication token to write arbitrary files on the host, potentially leading to code execution.

  • Potential arbitrary file writes on the host
  • Possible code execution as the P4 Search service account
  • Need to verify instance version and apply patches
  • Requirement to restrict access to the logging configuration interface

Technical summary

Perforce P4 Search prior to 2026.4.2 does not restrict file paths written through its logging configuration interface. An attacker holding the service authentication token can write arbitrary files on the host, potentially leading to code execution as the P4 Search service account. This vulnerability allows for potential arbitrary file writes on the host and possible code execution as the P4 Search service account. The logging configuration interface is a key area of concern, and defenders should focus on verifying instance versions and restricting access to this interface.

Defensive priority

Defenders should prioritize verifying and mitigating this vulnerability in Perforce P4 Search instances.

Recommended defensive actions

  • Verify Perforce P4 Search instance version and apply patches if necessary
  • Restrict access to the logging configuration interface
  • Monitor for suspicious file writes on the host
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review

Evidence notes

The CVE description indicates that Perforce P4 Search prior to 2026.4.2 does not restrict file paths written through its logging configuration interface, potentially allowing an attacker with the service authentication token to write arbitrary files on the host.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-103507 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-103507

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-103507 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-103507

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://portal.perforce.com/s/cve/a91Qi000003FE49IAG/arbitrary-filewrite-via-log-configuration-path-in-p4search

    [email protected]

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.