ExploitMatch
Back

CVE-2026-103511

Monitor on ThreatCluster

Description

Perforce P4 Search prior to 2026.4.2 does not validate file names supplied to its extension installation feature. An attacker with super-user or service-token privileges can write files with arbitrary content to the P4 Search installation directory.