Privilege Escalation Vulnerability in GoatCounter by Arp242
CVE-2026-108740

7.2HIGH

Key Information:

Vendor

Arp242

Vendor
CVE Published:
11 October 2026

What is CVE-2026-108740?

GoatCounter versions up to 2.7.0 are vulnerable to a mass assignment vulnerability found in the userPrefSave handler. This flaw allows authenticated users to exploit form-encoded requests to alter protected fields of accounts. Attackers can manipulate the system by submitting requests such as user.access[all]=* and user.email_verified=true to the /user/pref endpoint, effectively bypassing security measures intended to restrict access. This could potentially grant unauthorized superuser or admin privileges to those with only read access, raising significant concerns about account security and integrity.

Affected Version(s)

GoatCounter 0 <= 2.7.0

References

CVSS V4

Score:
7.2
Severity:
HIGH
Confidentiality:
Low
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

HaiND from the Post and Telecommunication Institute of Technology
.