github.comConfirmation
https://github.com/pear/pearweb/security/advisories/GHSA-p92v-9j73-fxx3 CVE-2026-25233
HIGH
PEAR Has a Roadmap Authorization Bypass via Operator Precedence Bug
Record summary
CVE-2026-25233 has a selected CVSS score of 7.1 (high).
Description
PEAR is a framework and distribution system for reusable PHP components. Prior to version 1.33.0, logic bug in the roadmap role check allows non-lead maintainers to create, update, or delete roadmaps. This issue has been patched in version 1.33.0.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Feb 4, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
pearwebBrowse pear / pearweb | CVE List | < 1.33.0 | affected |