CVE-2026-108740

Published: Ott 11, 2026 Last Modified: Ott 11, 2026
ExploitDB:
Other exploit source:
Google Dorks:
HIGH 7,2
Attack Vector: network
Attack Complexity: low
Privileges Required: low
User Interaction: none
Confidentiality: N/A
Integrity: N/A
Availability: N/A
HIGH 8,3
Attack Vector: network
Attack Complexity: low
Privileges Required: low
User Interaction: none
Scope: unchanged
Confidentiality: low
Integrity: high
Availability: high

Description

AI Translation Available

GoatCounter through 2.7.0 contains a mass assignment privilege escalation vulnerability in the userPrefSave handler that allows logged-in users to modify protected account fields via form-encoded requests. Attackers with read-only access can POST user.access[all]=* and user.email_verified=true to /user/pref, bypassing readonly tags to gain superuser or admin access.

915

Improperly Controlled Modification of Dynamically-Determined Object Attributes

Incomplete
Common Consequences
Security Scopes Affected:
Integrity Other
Potential Impacts:
Modify Application Data Execute Unauthorized Code Or Commands Varies By Context Alter Execution Logic
Applicable Platforms
Languages: Ruby, ASP.NET, PHP, Python, Not Language-Specific
View CWE Details
https://github.com/arp242/goatcounter
https://github.com/arp242/goatcounter/blob/7e91d8a9bdbb0dd48496e498c5680f8f3477…
https://github.com/arp242/goatcounter/blob/7e91d8a9bdbb0dd48496e498c5680f8f3477…
https://hackmd.io/@haind03/goatcounter-user-pref-access-mass-assignment-20261011
https://www.vulncheck.com/advisories/goatcounter-through-2.7.0-privilege-escala…