CVE-2026-25233: PEAR Has a Roadmap Authorization Bypass via Operator Precedence Bug
PEAR is a framework and distribution system for reusable PHP components. Prior to version 1.33.0, logic bug in the roadmap role check allows non-lead maintainers to create, update, or delete roadmaps. This issue has been patched in version 1.33.0.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-25233?
CVE-2026-25233 is considered a high severity vulnerability due to the potential for unauthorized access and manipulation of roadmaps in PEAR.
How do I fix CVE-2026-25233?
To fix CVE-2026-25233, upgrade PEAR to version 1.33.0 or later where the vulnerability has been patched.
Who is affected by CVE-2026-25233?
CVE-2026-25233 affects all versions of PEAR prior to 1.33.0, allowing non-lead maintainers to exploit the authorization bypass.
What types of issues can arise from CVE-2026-25233?
CVE-2026-25233 can lead to unauthorized users creating, updating, or deleting roadmaps, potentially disrupting project management.
Is there a specific version of PEAR that is safe from CVE-2026-25233?
Yes, any version of PEAR that is 1.33.0 or later is safe from the vulnerability identified as CVE-2026-25233.