Junglewise Threat Intelligence

CVE-2026-6902: Perforce Helix Core P4 Server code injection in Command-Line Client

CVE-2026-6902 · Severity: info · CVSS 7.7 · Published 2026-05-18

Vendors: Perforce.

Executive brief

A code injection vulnerability exists in the Perforce Helix Core P4 Server command-line client. Helix Core is a version control system used by large development teams to manage source code and digital assets. An attacker could exploit this flaw to execute unauthorized commands, potentially leading to full system compromise, data theft, or disruption of development operations.

Technical details

A code injection vulnerability (CWE-94) exists in the Command-Line Client component of Perforce P4 Server. The flaw allows an attacker to improperly control the generation of code, leading to unauthorized execution. According to the CVSS 4.0 vector, the attack is network-reachable and requires some user interaction, but carries high impact for confidentiality, integrity, and availability. The vulnerability is addressed in P4 Server version 2025.2 Patch 2.

Affected products

  • Perforce Helix Core P4 Server Prior to 2025.2 Patch 2

Timeline

  • 2026-05-18: disclosed: Initial publication of CVE-2026-6902
  • 2026-05-18: advisory: Perforce released security advisory and patch information

References