No analysis available yet.
No remediation available yet.
Tracking
Sign in to view the affected projects.
No advisories yet.
Sun, 11 Oct 2026 12:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | GoatCounter through 2.7.0 contains a mass assignment privilege escalation vulnerability in the userPrefSave handler that allows logged-in users to modify protected account fields via form-encoded requests. Attackers with read-only access can POST user.access[all]=* and user.email_verified=true to /user/pref, bypassing readonly tags to gain superuser or admin access. | |
| Title | GoatCounter through 2.7.0 Privilege Escalation via /user/pref Mass Assignment | |
| Weaknesses | CWE-915 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-10-11T12:19:44.911Z
Reserved: 2026-10-11T01:52:55.041Z
Link: CVE-2026-108740
No data.
Status : Received
Published: 2026-10-11T13:17:18.527
Modified: 2026-10-11T13:17:18.527
Link: CVE-2026-108740
No data.
OpenCVE Enrichment
No data.
-
CWE-915
Improperly Controlled Modification of Dynamically-Determined Object Attributes