VYPR
High severity8.3NVD Advisory· Published Oct 11, 2026

CVE-2026-108740

CVE-2026-108740

Description

GoatCounter through 2.7.0 contains a mass assignment privilege escalation vulnerability in the userPrefSave handler that allows logged-in users to modify protected account fields via form-encoded requests. Attackers with read-only access can POST user.access[all]=* and user.email_verified=true to /user/pref, bypassing readonly tags to gain superuser or admin access.

Patches

Vulnerability mechanics

References

4

News mentions

0

No linked articles in our index yet.