CVE-2026-16764

MEDIUM

OWASP DefectDojo API/Web serializers.py UserSerializer privileges management

Title source: cna
STIX 2.1

Description

A vulnerability was identified in OWASP DefectDojo 2.59.0. This issue affects the function UserSerializer of the file dojo/api_v2/serializers.py of the component API/Web. Such manipulation of the argument is_staff leads to improper privilege management. The attack may be performed from remote. The exploit is publicly available and might be used. Upgrading to version 2.58.3 and 3.0.0 is capable of addressing this issue. The name of the patch is 68a272f299d096249fd3ba9c2676bf69012857bf. It is advisable to upgrade the affected component. 2.59.0 was not intended to be released and has been removed.

References (8)

Core 8
Core References
Vdb Entry, Technical Description vdb-entry technical-description
VDB-382629 | OWASP DefectDojo API/Web serializers.py UserSerializer privileges management
https://vuldb.com/vuln/382629
Signature, Permissions Required signature permissions-required
VDB-382629 | CTI Indicators (IOB, IOC, TTP, IOA)
https://vuldb.com/vuln/382629/cti
Third Party Advisory third-party-advisory
CVE-2026-16764 | CVE Analysis and Report
https://vuldb.com/cve/CVE-2026-16764
Third Party Advisory third-party-advisory
Submit #861317 | djangoproject django-DefectDojo 2.59.0 CWE-269 - Improper Privilege Management
https://vuldb.com/submit/861317

Scores

CVSS v3 6.3
EPSS 0.0023
EPSS Percentile 14.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-266 CWE-269
Status published
Products (3)
OWASP/DefectDojo 2.58.3
OWASP/DefectDojo 2.59.0
OWASP/DefectDojo 3.0.0
Published Jul 23, 2026
Tracked Since Jul 24, 2026