CVE-2026-108740
Received Received - Intake

GoatCounter Privilege Escalation via Mass Assignment

Vulnerability report for CVE-2026-108740, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-11

Last updated on: 2026-10-11

Assigner: VulnCheck

Description

GoatCounter through 2.7.0 contains a mass assignment privilege escalation vulnerability in the userPrefSave handler that allows logged-in users to modify protected account fields via form-encoded requests. Attackers with read-only access can POST user.access[all]=* and user.email_verified=true to /user/pref, bypassing readonly tags to gain superuser or admin access.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-11
Last Modified
2026-10-11
Generated
2026-10-11
AI Q&A
2026-10-11
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
arp242 GoatCounter 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-915 The product receives input from an upstream component that specifies multiple attributes, properties, or fields that are to be initialized or updated in an object, but it does not properly control which attributes can be modified.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

GoatCounter through version 2.7.0 has a vulnerability where logged-in users can escalate privileges by modifying protected account fields. Attackers with read-only access can send specific form-encoded requests to /user/pref to gain superuser or admin access.

Detection Guidance

Check GoatCounter logs for POST requests to /user/pref with parameters like user.access[all]=* or user.email_verified=true. Monitor for unauthorized privilege changes or admin account modifications.

Impact Analysis

If exploited, this vulnerability allows attackers with minimal access to escalate privileges to superuser or admin levels. This could lead to unauthorized data access, modification, or deletion within the GoatCounter application.

Compliance Impact

This vulnerability could lead to unauthorized access or data breaches, which may violate GDPR's data protection requirements or HIPAA's security rules. Organizations using vulnerable versions may face compliance violations and legal penalties.

Mitigation Strategies

Update GoatCounter to the latest version beyond 2.7.0. Restrict user access to sensitive fields and review all admin accounts for unauthorized changes. Block suspicious POST requests to /user/pref at the firewall or WAF level.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-108740. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart