CVE-2026-16764
MEDIUMOWASP DefectDojo API/Web serializers.py UserSerializer privileges management
Title source: cnaDescription
A vulnerability was identified in OWASP DefectDojo 2.59.0. This issue affects the function UserSerializer of the file dojo/api_v2/serializers.py of the component API/Web. Such manipulation of the argument is_staff leads to improper privilege management. The attack may be performed from remote. The exploit is publicly available and might be used. Upgrading to version 2.58.3 and 3.0.0 is capable of addressing this issue. The name of the patch is 68a272f299d096249fd3ba9c2676bf69012857bf. It is advisable to upgrade the affected component. 2.59.0 was not intended to be released and has been removed.
References (8)
Core 8
Core References
Vdb Entry, Technical Description vdb-entry
technical-description
VDB-382629 | OWASP DefectDojo API/Web serializers.py UserSerializer privileges management
https://vuldb.com/vuln/382629
Signature, Permissions Required signature
permissions-required
VDB-382629 | CTI Indicators (IOB, IOC, TTP, IOA)
https://vuldb.com/vuln/382629/cti
Third Party Advisory third-party-advisory
CVE-2026-16764 | CVE Analysis and Report
https://vuldb.com/cve/CVE-2026-16764
Third Party Advisory third-party-advisory
Submit #861317 | djangoproject django-DefectDojo 2.59.0 CWE-269 - Improper Privilege Management
https://vuldb.com/submit/861317
Related related
https://github.com/DefectDojo/django-DefectDojo/security/advisories/GHSA-w2j3-x3j3-mm43
Patch issue-tracking
patch
https://github.com/DefectDojo/django-DefectDojo/pull/14952
Scores
CVSS v3
6.3
EPSS
0.0023
EPSS Percentile
14.3%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-266
CWE-269
Status
published
Products (3)
OWASP/DefectDojo
2.58.3
OWASP/DefectDojo
2.59.0
OWASP/DefectDojo
3.0.0
Published
Jul 23, 2026
Tracked Since
Jul 24, 2026