
Vulnerability in OWASP DefectDojo! Our analysts have found an Improper Privilege Management flaw identified in version 2.59.0, which resulted in the CVE-2026-16764. The vulnerability allows an authenticated low-privileged user to escalate their permissions to an administrative level by manipulating the is_staff parameter within the UserSerializer function, exploiting insufficient API validation. As a consequence, an attacker can gain full administrative access to the platform, view and modify vulnerability reports across the entire organization, compromise security triage workflows, and potentially hide or manipulate critical findings. In this post, we detail the root cause of the vulnerability, its exploitation via API, the fix implemented by the DefectDojo team, and the main recommendations for risk mitigation. Authors: Lucas Dantas is an Information Security professional with 2 years of experience at Hakai Security, working in Application Security (AppSec), Secure Development, and Offensive Security. Specialist in Threat Modeling, with experience in Secure SDLC, Code Review, Security Maturity Assessment, Web Pentesting, and vulnerability research Vivaldo Chagas, pentester at Hakai Security, with a background spanning application security, red team operations, and penetration testing. A native of Amazonas, Brazil, he built his career at the intersection of offensive security and attack surface analysis, relying on hands-on experience in corporate environments. Check out the technical details and the impact of this flaw in our full article: http://yokai.hakaisecurity.io/en-cve-2026-16764-missing-validation-full-access Wanna try out for yourself? Come check the challenge in Hacking Club! https://app.hackingclub.com/training/challenges/154
