CVE-2026-103512: falha de média gravidade em Perforce P4 (Helix Core)
Ticket host-binding bypass via spoofed client IP in P4Search
Publicada em
13Vexday Risk Score
Sem sinal de exploração. Nenhum artefato público de exploração conhecido até agora.
ssvc Trackcvss 5.3epss 0.4%
probabilidade de exploração
0.4%top 71% das CVEs
exploração observada
nãonenhuma fonte reporta
Perforce P4 Search prior to 2026.4.2 trusts a client-supplied address when validating certain authentication requests. An attacker holding a stolen P4 Server ticket can bypass host-based ticket restrictions and trusted-address controls, gaining access to P4 Search as the ticket's owner.
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
Produtos afetados
Perforce · P4 (Helix Core)CVEs relacionadas — Perforce P4 (Helix Core)
No mesmo produto, das mais perigosas para as menos.
CVE-2026-6902HIGHCode Injection in Perforce P4 (Helix Core)EPSS 0.7%CVE-2026-103507HIGHArbitrary file-write via log configuration path in P4SearchEPSS 0.5%CVE-2026-100102CRITICALRCE via exposed JDWP debug agent in P4SearchEPSS 0.4%CVE-2026-103510CRITICALAuthentication bypass via blank auth token in P4SearchEPSS 0.3%CVE-2026-103511MEDIUMArbitrary file-write via extension installation in P4SearchEPSS 0.3%