CVE-2026-108740 | arp242 GoatCounter up to 2.7.0 userPrefSave handler /user/pref access/email_verified dynamically-determined object attributes
A vulnerability classified as critical was found in arp242 GoatCounter up to 2.7.0. This issue affects the function userPrefSave of the file /user/pref of the component userPrefSave handler. The manipulation of the argument access/email_verified results in dynamically-determined object attributes.
This vulnerability is known as CVE-2026-108740. It is possible to launch the attack remotely. No exploit is available.VulDB Recent EntriesRead More