High severity8.3NVD Advisory· Published Oct 11, 2026
CVE-2026-108740
CVE-2026-108740
Description
GoatCounter through 2.7.0 contains a mass assignment privilege escalation vulnerability in the userPrefSave handler that allows logged-in users to modify protected account fields via form-encoded requests. Attackers with read-only access can POST user.access[all]=* and user.email_verified=true to /user/pref, bypassing readonly tags to gain superuser or admin access.
Patches
Vulnerability mechanics
References
4- github.com/arp242/goatcounter/blob/7e91d8a9bdbb0dd48496e498c5680f8f3477a1b4/handlers/settings_user.gonvd
- github.com/arp242/goatcounter/blob/7e91d8a9bdbb0dd48496e498c5680f8f3477a1b4/user.gonvd
- hackmd.io/@haind03/goatcounter-user-pref-access-mass-assignment-20261011nvd
- www.vulncheck.com/advisories/goatcounter-through-2.7.0-privilege-escalation-via-user-pref-mass-assignmentnvd
News mentions
0No linked articles in our index yet.