CVE-2026-6902Disclosure

LOWCVSS 7.7 · HIGH

Signal is active with 5 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

A Remote Code Execution vulnerability in P4 (Helix Core) Server's Command-Line Client, prior to the 2025.2 Patch 2, has been fixed to address potential security risks.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-94

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 7 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 5 signals
  • Disclosure: 4 classified signals
  • General: 2 classified signals
  • Peaked at 5 mentions on most recent observed day (2026-07-02)
  • 7 total mentions across 2 days

Deep dive

Activity timeline7 mentions / 2d
01345Mentions · 2026-05-18: 2Mentions · 2026-07-02: 5Patch / Workaround · 2026-05-18: 1Patch / Workaround · 2026-07-02: 1Technical Details · 2026-05-18: 1Technical Details · 2026-07-02: 405-1807-02
Signal classification3 categories
Disclosure
457.1%
General
228.6%
Patch
114.3%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-05-182
General1Patch1
2026-07-025
Disclosure4General1
Full discourse7 posts
  • Nicolas Krassas@Dinosn
    General

    Code Injection in Perforce Helix Core (CVE-2026-6902) https://www.imperva.com/blog/code-injection-in-perforce-helix-core-cve-2026-6902/

    Post summary

    The provided text only names the CVE and includes a link, without any indication of exploitation details, PoC, or remediation.

    0201002.4K
    160.8K followersView on X
  • DFIR Radar@DFIR_Radar
    Disclosure

    CVE-2026-6902 (CVSS 7.7) in Perforce Helix Core lets a rogue server write P4LOGINSSO=<shell command> into a victim's .p4config, executing arbitrary code on the next p4 command. #DFIR_Radar https://t.co/dctcRCwnJa

    Post summary

    The post announces CVE‑2026‑6902, a CVSS 7.7 flaw in Perforce Helix Core that lets a malicious server inject a shell command into a victim’s .p4config, enabling code execution on the next p4 command.

    10001207
    1.7K followersView on X
  • omvapt@omvapt
    Disclosure

    #Code_Injection in #Perforce_Helix Core (CVE-2026-6902) https://buff.ly/lDeIBw7 https://t.co/KwTPJpVh8f

    Post summary

    The tweet announces a newly disclosed code‑injection vulnerability in Perforce Helix Core (CVE‑2026‑6902) without providing further technical or exploit details.

    0000054
    388 followersView on X
  • kokumօtօ@__kokumoto
    Disclosure

    Perforce Helix Core (P4)にコードインジェクションの脆弱性。CVE-2026-6902はCVSSv4スコア7.7で、サーバ応答がリクエストに対応したものかをクライアントが検証していないもの。公式はv2026.1 (May 2026)で対応済としているが、内容は構成ファイルの上書きだけ防ぐ緩和策。 https://www.imperva.com/blog/code-injection-in-perforce-helix-core-cve-2026-6902/

    Post summary

    CVE‑2026‑6902 is a code injection flaw in Perforce Helix Core with a CVSSv4 score of 7.7; client verification is missing, and the vendor has issued a mitigation in v2026.1 to prevent configuration file overwrites.

    00000810
    7.6K followersView on X
  • Jim Rigney@RigneySec
    Disclosure

    Code Injection in Perforce Helix Core (CVE-2026-6902) https://www.imperva.com/blog/code-injection-in-perforce-helix-core-cve-2026-6902/?utm_source=dlvr.it&utm_medium=twitter https://t.co/r4x6OA4Opw

    Post summary

    The text references a blog post announcing a code injection vulnerability in Perforce Helix Core (CVE‑2026‑6902) but provides no further details about PoC, exploit availability, active usage, patching, or mitigation.

    0000041
    681 followersView on X
  • CVEarity@CVEarity
    General

    ⚡ New CVE Alert: CVE-2026-6902 📊 Severity: 7.7 🚨 Risk Level: High 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-6902 #CVE-2026-6902 #CVE #High  #CyberSecurity #InfoSec https://t.co/z3CSWdZVms

    Post summary

    A new vulnerability (CVE‑2026‑6902) is announced as high severity, but no technical or exploit details, patches, or claims of active exploitation are provided.

    0000070
    160 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Patch

    CVE-2026-6902 Command-Line Client Vulnerability in P4 Server Prior to 2025.2 Patch 2 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-6902

    Post summary

    The entry announces a command‑line client vulnerability in P4 Server and indicates that a patch (2025.2 Patch 2) has been released, with no evidence of proofs of concept, exploitation, or debunking.

    0000068
    4.0K followersView on X

Explore more