Skip to content
Threat Feed
high advisory

Privilege Escalation in GoatCounter via Mass Assignment

GoatCounter versions 2.7.0 and earlier are vulnerable to a mass assignment flaw in the userPrefSave handler, enabling authenticated users to escalate privileges to administrator status.

CVE search metadata

CVE search record: CVE-2026-108740. Severity: high. CVSS: 8.3. KEV: no. Product: GoatCounter (<= 2.7.0). Brief: Privilege Escalation in GoatCounter via Mass Assignment. Brief link: https://feed.craftedsignal.io/briefs/2026-10-goatcounter-privesc/

GoatCounter versions through 2.7.0 contain a mass assignment privilege escalation vulnerability located in the userPrefSave handler. This vulnerability arises from improper validation of form-encoded requests submitted to the /user/pref endpoint. Authenticated users with read-only access can exploit this flaw to overwrite protected account fields by including unauthorized keys in their POST requests. Specifically, by injecting parameters such as 'user.access[all]=*' and 'user.email_verified=true', a standard user can circumvent application logic and grant themselves superuser or administrative privileges. This vulnerability is critical for organizations relying on GoatCounter for internal analytics, as it allows unauthorized users to gain full control over the analytics dashboard and account settings.

Impact

Successful exploitation allows a low-privileged authenticated user to gain full administrative control over the GoatCounter instance. This facilitates unauthorized access to potentially sensitive analytics data, modification of site configurations, and management of other user accounts within the environment.

Recommendation

  • Upgrade GoatCounter to a version greater than 2.7.0 immediately.
  • Implement strict monitoring on the /user/pref endpoint for anomalous POST requests containing unexpected parameter structures, specifically those attempting to set access control fields.
  • Audit existing administrative user accounts for unauthorized additions or unexpected changes to account permissions.

Immediate actions

Upgrade GoatCounter to version 2.7.1 or higher

IT Operations 48h

Mitigations

Upgrade GoatCounter software to version 2.7.1+

immediate IT Operations

CVE-2026-108740