OFFLINE
Awaiting data
Security intelligence
MinorCritical vulnerability

CVE-2026-108740 (CVSS 7.2)

NVD · officialPublished Oct 11, 2026Risk 23/100

GoatCounter through 2.7.0 contains a mass assignment privilege escalation vulnerability in the userPrefSave handler that allows logged-in users to modify protected account fields via form-encoded requests. Attackers with read-only access can POST user.access[all]=* and user.email_verified=true to /user/pref, bypassing readonly tags to gain superuser or admin access.

CVSS
7.2
AV:NetworkAC:LowPR:LowUI:None

This record is attributed to NVD. Exploitation status and remediation guidance are kept separate from the vulnerability's technical severity.

Open primary source