PatchSiren

arp242 CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH arp242 CVE published 2026-10-11

CVE-2026-108740

CVE-2026-108740 is a high-severity privilege escalation vulnerability in GoatCounter versions up to 2.7.0. The vulnerability allows logged-in users to modify protected account fields via mass assignment, potentially leading to elevated access. This issue arises from inadequate validation of user input in the userPrefSave handler, enabling attackers to manipulate account settings and gain unauthorized acce [truncated]