<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>GoatCounter (&lt;= 2.7.0) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/goatcounter--2.7.0/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Sun, 11 Oct 2026 14:01:33 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/goatcounter--2.7.0/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Privilege Escalation in GoatCounter via Mass Assignment</title><link>https://feed.craftedsignal.io/briefs/2026-10-goatcounter-privesc/</link><pubDate>Sun, 11 Oct 2026 14:01:33 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-goatcounter-privesc/</guid><description>GoatCounter versions 2.7.0 and earlier are vulnerable to a mass assignment flaw in the userPrefSave handler, enabling authenticated users to escalate privileges to administrator status.</description><content:encoded><![CDATA[<p>GoatCounter versions through 2.7.0 contain a mass assignment privilege escalation vulnerability located in the userPrefSave handler. This vulnerability arises from improper validation of form-encoded requests submitted to the /user/pref endpoint. Authenticated users with read-only access can exploit this flaw to overwrite protected account fields by including unauthorized keys in their POST requests. Specifically, by injecting parameters such as 'user.access[all]=*' and 'user.email_verified=true', a standard user can circumvent application logic and grant themselves superuser or administrative privileges. This vulnerability is critical for organizations relying on GoatCounter for internal analytics, as it allows unauthorized users to gain full control over the analytics dashboard and account settings.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows a low-privileged authenticated user to gain full administrative control over the GoatCounter instance. This facilitates unauthorized access to potentially sensitive analytics data, modification of site configurations, and management of other user accounts within the environment.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Upgrade GoatCounter to a version greater than 2.7.0 immediately.</li>
<li>Implement strict monitoring on the /user/pref endpoint for anomalous POST requests containing unexpected parameter structures, specifically those attempting to set access control fields.</li>
<li>Audit existing administrative user accounts for unauthorized additions or unexpected changes to account permissions.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>privilege-escalation</category><category>web-vulnerability</category></item></channel></rss>