CVE-2026-25235CWE-337

PEAR Has a Predictable Verification Hash in Election Account Requests

High · published February 3, 2026

CVSS v4.0
8.2
EPSS
0%
Percentile
16.9
In the wild
Unconfirmed
What it is

⚡ An attacker could guess verification tokens and potentially hijack election account requests with ease! This vulnerability in PEAR is a surprising oversight that needs your attention. 🔥 Think of it like a restaurant that gives every customer a unique number for their order, but the numbers are just sequential. If someone overhears or sees the sequence, they could easily place an unauthorized order claiming they're someone else! If exploited, an attacker could verify election account requests without proper authorization, undermining the integrity of the entire process. This could lead to unauthorized access, manipulation of election results, or other devastating consequences that shake public trust.

Put simply

Think of it like a restaurant that gives every customer a unique number for their order, but the numbers are just sequential. If someone overhears or sees the sequence, they could easily place an unauthorized order claiming they're someone else! This vulnerability arises from predictable verification hashes used in the PEAR framework, which allow attackers to guess verification tokens intended for securing election account requests. This flaw poses a significant security risk for applications relying on PEAR prior to version 1.33.0.

What to do

If exploited, an attacker could verify election account requests without proper authorization, undermining the integrity of the entire process. This could lead to unauthorized access, manipulation of election results, or other devastating consequences that shake public trust. Update PEAR to version 1.33.0 immediately to fix this issue and prevent unauthorized access. Additionally, review your application's security policies to ensure robust token generation and validation processes are in place. You've got this! Update your framework and reinforce your security measures to keep your applications safe! 🛡️

The record
Technical detail
CVSS v4.0
8.2 · HIGH
Vector
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
EPSS
0.00255 · 16.9th percentile
Weakness
CWE-337 · Predictable Seed in Pseudo-Random Number Generator (PRNG)
Published
2026-02-03T18:29Z
EPSS history
Timeline
  • 03 FEB 18:29Z
    PEAR Has a Predictable Verification Hash in Election Account Requests
    cvelistv5