PT-2026-6284 · Git+2 · Pearweb+1

Megamansec

·

Published

2026-02-03

·

Updated

2026-02-03

·

CVE-2026-25235

CVSS v4.0

8.2

High

VectorAV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions PEAR versions prior to 1.33.0
Description PEAR is a framework and distribution system for reusable PHP components. Predictable verification hashes may allow attackers to guess verification tokens and potentially verify election account requests without authorization.
Recommendations Update to version 1.33.0.

Exploit

Fix

Weakness Enumeration

Related Identifiers

CVE-2026-25235
GHSA-477R-4CMW-3CGF

Affected Products

Pearweb
Php Pear