{"id":"CVE-2026-108740","aliases":[],"url":"https://o3.security/vulnerability/CVE-2026-108740","summary":"GoatCounter through 2.7.0 contains a mass assignment privilege escalation vulnerability in the userPrefSave handler that allows logged-in users to modify protected account fields via…","details":"GoatCounter through 2.7.0 contains a mass assignment privilege escalation vulnerability in the userPrefSave handler that allows logged-in users to modify protected account fields via form-encoded requests. Attackers with read-only access can POST user.access[all]=* and user.email_verified=true to /user/pref, bypassing readonly tags to gain superuser or admin access.","published":"2026-10-11T13:17:18.527","modified":"2026-10-11T13:17:18.527","cvss":{"score":8.3,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[],"fix":null,"references":[{"type":"WEB","url":"https://github.com/arp242/goatcounter"},{"type":"WEB","url":"https://github.com/arp242/goatcounter/blob/7e91d8a9bdbb0dd48496e498c5680f8f3477a1b4/handlers/settings_user.go#L33-L99"},{"type":"WEB","url":"https://github.com/arp242/goatcounter/blob/7e91d8a9bdbb0dd48496e498c5680f8f3477a1b4/user.go#L191-L218"},{"type":"WEB","url":"https://hackmd.io/@haind03/goatcounter-user-pref-access-mass-assignment-20261011"},{"type":"WEB","url":"https://www.vulncheck.com/advisories/goatcounter-through-2.7.0-privilege-escalation-via-user-pref-mass-assignment"}],"provenance":{"sources":["OSV.dev","NVD","FIRST.org (EPSS)"],"lastVerified":"2026-10-11T13:17:18.527"}}