A Remote Code Execution vulnerability in P4 (Helix Core) Server's Command-Line Client, prior to the 2025.2 Patch 2, has been fixed to address potential security risks.

Project Subscriptions

Vendors Products
Perforce Subscribe
Helix Core Subscribe
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Wed, 20 May 2026 06:30:00 +0000

Type Values Removed Values Added
Description A vulnerability in Command-Line Client in P4 Server prior to the 2025.2 Patch 2, identified as CVE-2026-6902, has been fixed in P4 Server to address potential security risks. A Remote Code Execution vulnerability in P4 (Helix Core) Server's Command-Line Client, prior to the 2025.2 Patch 2, has been fixed to address potential security risks.

Tue, 19 May 2026 08:30:00 +0000

Type Values Removed Values Added
First Time appeared Perforce
Perforce helix Core
Vendors & Products Perforce
Perforce helix Core

Mon, 18 May 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 18 May 2026 09:00:00 +0000

Type Values Removed Values Added
Description A vulnerability in Command-Line Client in P4 Server prior to the 2025.2 Patch 2, identified as CVE-2026-6902, has been fixed in P4 Server to address potential security risks.
Title Code Injection in Perforce P4 (Helix Core)
Weaknesses CWE-94
References
Metrics cvssV4_0

{'score': 7.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: Perforce

Published:

Updated: 2026-05-20T05:49:13.390Z

Reserved: 2026-04-23T09:27:12.742Z

Link: CVE-2026-6902

cve-icon Vulnrichment

Updated: 2026-05-18T12:42:39.195Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-05-18T09:16:24.283

Modified: 2026-05-20T07:16:16.187

Link: CVE-2026-6902

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-20T08:30:25Z

Weaknesses