Sceawere

Vulnerability Detail

CVE-2026-108740UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

GoatCounter Mass Assignment Privilege Escalation

Vulnerability Metadata

Severity
High
Score / CVSS
8.3
Creation Date
4h ago
Vendor
arp242
Product
GoatCounter
Attack Type
Improperly Controlled Modification of Dynamically-Determined Object Attributes
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

GoatCounter through 2.7.0 contains a mass assignment privilege escalation vulnerability in the userPrefSave handler that allows logged-in users to modify protected account fields via form-encoded requests. Attackers with read-only access can POST user.access[all]=* and user.email_verified=true to /user/pref, bypassing readonly tags to gain superuser or admin access.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "8.3",
  "pubDate": "2026-10-11T13:17:18.527Z",
  "pubdate": "2026-10-11T13:17:18.527Z",
  "executiveSummary": "A mass assignment vulnerability exists in GoatCounter versions through 2.7.0, residing within the userPrefSave handler.\nThis vulnerability permits authenticated users, including those with restricted, read-only permissions, to elevate their privileges to superuser or administrative status.\nThe flaw stems from insufficient input validation and improper binding of request parameters, which fails to restrict access to sensitive account attributes during the processing of form-encoded requests.\nBy manipulating specific fields during a POST request to the /user/pref endpoint, an attacker can bypass access control logic enforced by readonly tags.\nThe successful exploitation of this vulnerability results in full administrative control over the affected GoatCounter instance.\nThe risk is considered critical, as it allows for complete system compromise by standard authenticated users, facilitating unauthorized data access, administrative configuration changes, and potential system-wide disruption.",
  "technicalDetails": "The vulnerability is classified as a mass assignment (or over-posting) vulnerability located in the userPrefSave handler, which is responsible for processing user preference updates in GoatCounter versions through 2.7.0.\nThe root cause of this flaw is the application's failure to implement an effective allow-list or filter on incoming request parameters that are automatically bound to the user object during the save process.\nWhen a user sends a POST request to the /user/pref endpoint, the backend mechanism parses the form-encoded data and maps the input keys directly to the user model attributes. Because the application logic fails to properly sanitize or validate these incoming fields against the user's current authorization scope, it permits the injection of protected attributes that should only be modified by authorized administrators.\nAn attacker can exploit this by crafting a specifically formatted POST request containing key-value pairs that target high-privilege configuration fields. Specifically, injecting 'user.access[all]=*' and 'user.email_verified=true' into the form data overrides the intended application constraints. Although the UI or the system may label certain fields as 'readonly' or apply client-side restrictions, the server-side implementation blindly accepts these parameter updates, effectively bypassing the access control layer.\nThe attack flow proceeds as follows: First, the attacker must have a valid authenticated session on the target GoatCounter instance, even if the account is limited to read-only access. Second, the attacker intercepts or manually constructs a POST request directed at the /user/pref path. Third, the attacker appends the malicious parameters (user.access[all] and user.email_verified) to the payload. Fourth, the server-side userPrefSave handler processes these parameters and persists the modified, escalated privilege state to the database.\nThe post-exploitation impact is severe, as the attacker achieves administrative privileges, allowing them to manage other users, view sensitive analytics data, or modify system-wide settings. Because this occurs at the application object-binding layer, it successfully circumvents standard middleware or authorization checks that were expected to protect administrative fields, rendering the internal state of the user record inconsistent with the intended security model."
}
CVE-2026-108740: GoatCounter Mass Assignment Privilege Escalation (HIGH Severity, CVSS: 8.3) | Sceawere