CVE-2026-108740
HIGH
7,2
Source: [email protected]
Attack Vector: network
Attack Complexity: low
Privileges Required: low
User Interaction: none
Confidentiality: N/A
Integrity: N/A
Availability: N/A
HIGH
8,3
Source: [email protected]
Attack Vector: network
Attack Complexity: low
Privileges Required: low
User Interaction: none
Scope: unchanged
Confidentiality: low
Integrity: high
Availability: high
Description
AI Translation Available
GoatCounter through 2.7.0 contains a mass assignment privilege escalation vulnerability in the userPrefSave handler that allows logged-in users to modify protected account fields via form-encoded requests. Attackers with read-only access can POST user.access[all]=* and user.email_verified=true to /user/pref, bypassing readonly tags to gain superuser or admin access.
915
Improperly Controlled Modification of Dynamically-Determined Object Attributes
IncompleteCommon Consequences
Security Scopes Affected:
Integrity
Other
Potential Impacts:
Modify Application Data
Execute Unauthorized Code Or Commands
Varies By Context
Alter Execution Logic
Applicable Platforms
Languages:
Ruby, ASP.NET, PHP, Python, Not Language-Specific
https://github.com/arp242/goatcounter
https://github.com/arp242/goatcounter/blob/7e91d8a9bdbb0dd48496e498c5680f8f3477…
https://github.com/arp242/goatcounter/blob/7e91d8a9bdbb0dd48496e498c5680f8f3477…
https://hackmd.io/@haind03/goatcounter-user-pref-access-mass-assignment-20261011
https://www.vulncheck.com/advisories/goatcounter-through-2.7.0-privilege-escala…