CVE-2026-16764 Details
Description
A vulnerability was identified in OWASP DefectDojo 2.59.0. This issue affects the function UserSerializer of the file dojo/api_v2/serializers.py of the component API/Web. Such manipulation of the argument is_staff leads to improper privilege management. The attack may be performed from remote. The exploit is publicly available and might be used. Upgrading to version 2.58.3 and 3.0.0 is capable of addressing this issue. The name of the patch is 68a272f299d096249fd3ba9c2676bf69012857bf. It is advisable to upgrade the affected component. 2.59.0 was not intended to be released and has been removed.
A vulnerability in OWASP DefectDojo version 2.59.0 allows users with limited permissions to improperly manage privileges through the API. This issue arises in the UserSerializer component, where the is_staff attribute can be manipulated, potentially leading to unauthorized access rights. The vulnerability can be exploited remotely, and a public exploit is available.
Users are advised to upgrade to DefectDojo versions 2.58.3 or 3.0.0. Version 2.59.0 has been removed as it was not intended for release.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jul 23, 2026CISA-ADP
Assessed Jul 24, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/DefectDojo/django-DefectDojo/commit/68a272f299d096249fd3ba9c2676bf69012857bf | [email protected] | Source CodeVendor |
| https://github.com/DefectDojo/django-DefectDojo/pull/14952 | [email protected] | Issue TrackingVendor |
| https://github.com/DefectDojo/django-DefectDojo/releases/tag/3.0.0 | [email protected] | Release NotesVendor |
| https://github.com/DefectDojo/django-DefectDojo/security/advisories/GHSA-w2j3-x3j3-mm43 | [email protected] | AdvisoryRemedyVendor |
| https://vuldb.com/cve/CVE-2026-16764 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/submit/861317 | [email protected] | Permission Required |
| https://vuldb.com/vuln/382629 | [email protected] | Permission Required |
| https://vuldb.com/vuln/382629/cti | [email protected] | Content Wall |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-266 | Incorrect Privilege Assignment | [email protected] |
| CWE-269 | Improper Privilege Management | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| OWASP DefectDojo | 2.59.0 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 24, 2026 | CVE Modified | CISA-ADP |
| Jul 23, 2026 | New CVE Received | [email protected] |
Volerion