PatchSiren

Perforce CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM Perforce CVE published 2026-10-05

CVE-2026-103512

CVE-2026-103512 debrief based on CVE Program and NVD records. The vulnerability in Perforce P4 Search prior to 2026.4.2 allows an attacker with a stolen P4 Server ticket to bypass host-based ticket restrictions and trusted-address controls, gaining access to P4 Search as the ticket's owner. This medium-severity vulnerability requires review and update of P4 Search systems to version 2026.4.2 or later, res [truncated]

MEDIUM Perforce CVE published 2026-10-05

CVE-2026-103511

CVE-2026-103511 debrief based on the supplied source corpus. The CVE record was published on 2026-10-05T09:17:07.113Z and has not been modified since then. Perforce P4 Search prior to 2026.4.2 does not validate file names supplied to its extension installation feature, allowing an attacker with super-user or service-token privileges to write files with arbitrary content to the P4 Search installation direc [truncated]

CRITICAL Perforce CVE published 2026-10-05

CVE-2026-103510

CVE-2026-103510 is a critical vulnerability in P4 Search that can allow unauthenticated attackers to gain high privileges, potentially leading to system compromise. The vulnerability exists in P4 Search prior to version 2026.4.2, where the service authentication token is not handled securely, allowing an attacker with network access to obtain the highest application privilege. This could lead to the compr [truncated]

HIGH Perforce CVE published 2026-10-05

CVE-2026-103507

CVE-2026-103507 debrief based on CVE Program and NVD records. The vulnerability in Perforce P4 Search prior to 2026.4.2 allows an attacker with the service authentication token to write arbitrary files on the host through its logging configuration interface, potentially leading to code execution as the P4 Search service account. This issue affects defenders responsible for Perforce P4 Search instances, wh [truncated]

CRITICAL Perforce CVE published 2026-10-05

CVE-2026-100102

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-10-05T09:17:05.540Z and has not been modified since then. The vulnerability affects Perforce P4 Search container images prior to version 2026.4.2, enabling an unauthenticated Java debug interface. This interface can be exploited by an attacker with network access to execute arbitrary code as the P4 Sea [truncated]

CRITICAL Perforce CVE published 2026-09-11

CVE-2026-89212

A critical vulnerability was found in Akana API Platform, affecting multiple versions, including 2026.1, 2025.1.1, and all versions before 2024.1.6. This flaw results in XML external entity (XXE) during XML-to-JSON processing, allowing for potential security risks. The issue has been addressed with a security patch in the latest release of supported versions.

HIGH Perforce CVE published 2026-07-16

CVE-2026-14254

CVE-2026-14254 is a high-severity vulnerability in Delphix Continuous Data, involving a race condition in the account lockout mechanism. This condition allows an attacker to bypass the lockout threshold by making concurrent authentication requests, defeating brute-force protections. The vulnerability enables continued password guessing against a targeted account, posing a significant risk to Delphix Conti [truncated]

HIGH Perforce CVE published 2026-05-18

CVE-2026-6902

CVE-2026-6902 describes a code-injection weakness in the P4 Server command-line client that was fixed before version 2025.2 Patch 2. NVD rates the issue HIGH with a CVSS v4 score of 7.7 and maps it to CWE-94. The available record is brief, but it indicates a network-reachable issue that may require user interaction and could affect confidentiality, integrity, and availability if triggered.