PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-6902 Perforce CVE debrief

CVE-2026-6902 describes a code-injection weakness in the P4 Server command-line client that was fixed before version 2025.2 Patch 2. NVD rates the issue HIGH with a CVSS v4 score of 7.7 and maps it to CWE-94. The available record is brief, but it indicates a network-reachable issue that may require user interaction and could affect confidentiality, integrity, and availability if triggered.

Vendor
Perforce
Product
P4 (Helix Core)
CVSS
HIGH 7.7
CISA KEV
Not listed in stored evidence
Original CVE published
2026-05-18
Original CVE updated
2026-05-20
Advisory published
2026-05-18
Advisory updated
2026-05-20

Who should care

Administrators, security teams, and developers operating P4 Server deployments should care, especially where the command-line client is used in automated workflows or by privileged users. Organizations that rely on Perforce-adjacent tooling or packaging should also verify whether their installations are on a fixed release.

Technical summary

The supplied NVD record for CVE-2026-6902 identifies a vulnerability in the Command-Line Client in P4 Server prior to 2025.2 Patch 2. The weakness is classified as CWE-94 (code injection). NVD's CVSS v4 vector indicates network attack potential, no privileges required, user interaction required, and high potential impact to confidentiality, integrity, and availability. The public detail is limited to the record and referenced advisory title, so no more specific exploitation path is supported by the supplied corpus.

Defensive priority

HIGH

Recommended defensive actions

  • Upgrade P4 Server to 2025.2 Patch 2 or later.
  • Inventory all P4 Server instances and confirm which ones use the affected command-line client.
  • Review automation, scripts, and user workflows that invoke the command-line client, especially where untrusted input may be processed.
  • Limit exposure of administrative or interactive workflows to trusted users until patched.
  • Monitor vendor advisories and the official NVD record for any follow-up guidance or updated scope details.

Evidence notes

This debrief uses only the supplied NVD record and its linked official reference. The NVD metadata lists the weakness as CWE-94 and the CVSS v4 vector as 7.7 HIGH. The vendor attribution in the prompt is low confidence and marked for review, with only a reference-domain hint toward Perforce. No exploit details, affected-version breadth beyond "prior to 2025.2 Patch 2," or remediation specifics beyond upgrading are supported by the source corpus.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-6902 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-6902

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-6902 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-6902

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.