CVE-2026-103512: fallo de gravedad media en Perforce P4 (Helix Core)
Ticket host-binding bypass via spoofed client IP in P4Search
Publicada el
13Vexday Risk Score
Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.
ssvc Trackcvss 5.3epss 0.4%
probabilidad de explotación
0.4%top 71% de las CVE
explotación observada
noninguna fuente lo reporta
Perforce P4 Search prior to 2026.4.2 trusts a client-supplied address when validating certain authentication requests. An attacker holding a stolen P4 Server ticket can bypass host-based ticket restrictions and trusted-address controls, gaining access to P4 Search as the ticket's owner.
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
Productos afectados
Perforce · P4 (Helix Core)CVEs relacionadas — Perforce P4 (Helix Core)
En el mismo producto, de las más peligrosas a las menos.
CVE-2026-6902HIGHCode Injection in Perforce P4 (Helix Core)EPSS 0.7%CVE-2026-103507HIGHArbitrary file-write via log configuration path in P4SearchEPSS 0.5%CVE-2026-100102CRITICALRCE via exposed JDWP debug agent in P4SearchEPSS 0.4%CVE-2026-103510CRITICALAuthentication bypass via blank auth token in P4SearchEPSS 0.3%CVE-2026-103511MEDIUMArbitrary file-write via extension installation in P4SearchEPSS 0.3%