github.comConfirmation
https://github.com/pear/pearweb/security/advisories/GHSA-477r-4cmw-3cgf CVE-2026-25235
HIGH
PEAR Has a Predictable Verification Hash in Election Account Requests
Record summary
CVE-2026-25235 has a selected CVSS score of 8.2 (high).
Description
PEAR is a framework and distribution system for reusable PHP components. Prior to version 1.33.0, predictable verification hashes may allow attackers to guess verification tokens and potentially verify election account requests without authorization. This issue has been patched in version 1.33.0.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableYes
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Feb 4, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
pearwebBrowse pear / pearweb | CVE List | < 1.33.0 | affected |