CVE-2026-25233CWE-783

PEAR Has a Roadmap Authorization Bypass via Operator Precedence Bug

High · published February 3, 2026

CVSS v4.0
7.1
EPSS
0%
Percentile
24.5
In the wild
Unconfirmed
What it is

⚡ A logic bug in PEAR lets non-lead maintainers take control of roadmaps! 🚧 Think of this like a restaurant where waitstaff can rewrite the menu without the chef's approval, potentially leading to some questionable dish choices. Just like a rogue waiter could spoil the special of the day, the wrong maintainer could alter project direction. This could allow unauthorized users to create, update, or delete crucial project roadmaps, jeopardizing the integrity and future direction of your application. Imagine someone hijacking the steering wheel while you're on a road trip—chaos is bound to ensue!

Put simply

Think of this like a restaurant where waitstaff can rewrite the menu without the chef's approval, potentially leading to some questionable dish choices. Just like a rogue waiter could spoil the special of the day, the wrong maintainer could alter project direction. This vulnerability arises from a logic flaw in the roadmap role check within PEAR, allowing users without proper authority to manipulate critical project components.

What to do

This could allow unauthorized users to create, update, or delete crucial project roadmaps, jeopardizing the integrity and future direction of your application. Imagine someone hijacking the steering wheel while you're on a road trip—chaos is bound to ensue! Immediately upgrade to PEAR version 1.33.0 or later to close this security gap. Additionally, conduct a review of user roles and permissions to ensure only authorized personnel have access to sensitive project features. You've got this! With the right steps, you can secure your project and keep it on the right path! 🛡️

The record
Technical detail
CVSS v4.0
7.1 · HIGH
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
EPSS
0.00319 · 24.5th percentile
Weakness
CWE-783 · Operator Precedence Logic Error
Published
2026-02-03T18:29Z
EPSS history
Timeline
  • 03 FEB 18:29Z
    PEAR Has a Roadmap Authorization Bypass via Operator Precedence Bug
    cvelistv5