Privilege Escalation Vulnerability in GoatCounter by Arp242
CVE-2026-108740
7.2HIGH
What is CVE-2026-108740?
GoatCounter versions up to 2.7.0 are vulnerable to a mass assignment vulnerability found in the userPrefSave handler. This flaw allows authenticated users to exploit form-encoded requests to alter protected fields of accounts. Attackers can manipulate the system by submitting requests such as user.access[all]=* and user.email_verified=true to the /user/pref endpoint, effectively bypassing security measures intended to restrict access. This could potentially grant unauthorized superuser or admin privileges to those with only read access, raising significant concerns about account security and integrity.
Affected Version(s)
GoatCounter 0 <= 2.7.0
References
CVSS V4
Score:
7.2
Severity:
HIGH
Confidentiality:
Low
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
HaiND from the Post and Telecommunication Institute of Technology
