๐Ÿ” CVE Alert

CVE-2026-108740

HIGH 8.3

GoatCounter through 2.7.0 Privilege Escalation via /user/pref Mass Assignment

CVSS Score
8.3
EPSS Score
0.0%
EPSS Percentile
0th

GoatCounter through 2.7.0 contains a mass assignment privilege escalation vulnerability in the userPrefSave handler that allows logged-in users to modify protected account fields via form-encoded requests. Attackers with read-only access can POST user.access[all]=* and user.email_verified=true to /user/pref, bypassing readonly tags to gain superuser or admin access.

CWE CWE-915
Vendor arp242
Product goatcounter
Published Oct 11, 2026
Stay Ahead of the Next One

Get instant alerts for arp242 goatcounter

Be the first to know when new high vulnerabilities affecting arp242 goatcounter are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:H
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
High
Availability
High

Affected Versions

arp242 / GoatCounter
0 โ‰ค 2.7.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
hackmd.io: https://hackmd.io/@haind03/goatcounter-user-pref-access-mass-assignment-20261011 github.com: https://github.com/arp242/goatcounter/blob/7e91d8a9bdbb0dd48496e498c5680f8f3477a1b4/handlers/settings_user.go#L33-L99 github.com: https://github.com/arp242/goatcounter/blob/7e91d8a9bdbb0dd48496e498c5680f8f3477a1b4/user.go#L191-L218 github.com: https://github.com/arp242/goatcounter vulncheck.com: https://www.vulncheck.com/advisories/goatcounter-through-2.7.0-privilege-escalation-via-user-pref-mass-assignment

Credits

HaiND from the Post and Telecommunication Institute of Technology