CVE-2026-6902: Code Injection in Perforce P4 (Helix Core)
A Remote Code Execution vulnerability in P4 (Helix Core) Server's Command-Line Client, prior to the 2025.2 Patch 2, has been fixed to address potential security risks.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
P4 (Helix Core) Server - Command-Line Clientto a version that resolves this vulnerability.Fixed in 2025.2 Patch 2
Event History
Frequently Asked Questions
What is the severity of CVE-2026-6902?
CVE-2026-6902 is considered a critical vulnerability due to potential code injection risks.
How do I fix CVE-2026-6902?
To fix CVE-2026-6902, upgrade your Perforce P4 Server to version 2025.2 Patch 2 or later.
Which versions of Perforce P4 Server are affected by CVE-2026-6902?
CVE-2026-6902 affects all versions of Perforce P4 Server prior to 2025.2 Patch 2.
What could happen if CVE-2026-6902 is exploited?
If exploited, CVE-2026-6902 could allow an attacker to execute arbitrary code on the vulnerable server.
Is there a workaround for CVE-2026-6902?
There are no known workarounds for CVE-2026-6902, so immediate patching is recommended.