CVE-2026-25235: PEAR Has a Predictable Verification Hash in Election Account Requests
PEAR is a framework and distribution system for reusable PHP components. Prior to version 1.33.0, predictable verification hashes may allow attackers to guess verification tokens and potentially verify election account requests without authorization. This issue has been patched in version 1.33.0.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-25235?
CVE-2026-25235 is considered a high severity vulnerability due to its potential exploitation allowing attackers to guess verification tokens.
How do I fix CVE-2026-25235?
To fix CVE-2026-25235, upgrade PEAR to version 1.33.0 or later to eliminate predictable verification hashes.
Who is affected by CVE-2026-25235?
CVE-2026-25235 affects users of PEAR prior to version 1.33.0, specifically those using the framework for PHP components.
What can attackers do with CVE-2026-25235?
Attackers can exploit CVE-2026-25235 to predict and guess verification tokens, potentially gaining unauthorized access to election account requests.
Is there a workaround for CVE-2026-25235 if I can't upgrade?
There are no recommended workarounds for CVE-2026-25235, and users should prioritize upgrading to the patched version.