CVE-2026-16764

LOWCVSS 2.1 · LOW

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability was identified in OWASP DefectDojo 2.59.0. This issue affects the function UserSerializer of the file dojo/api_v2/serializers.py of the component API/Web. Such manipulation of the argument is_staff leads to improper privilege management. The attack may be performed from remote. The exploit is publicly available and might be used. Upgrading to version 2.58.3 and 3.0.0 is capable of addressing this issue. The name of the patch is 68a272f299d096249fd3ba9c2676bf69012857bf. It is advisable to upgrade the affected component. 2.59.0 was not intended to be released and has been removed.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-266CWE-269

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-09-25: 109-25
Referenced assets2 URLs
Full discourse1 post
  • Hakai Offsec@HakaiOffsec

    Vulnerability in OWASP DefectDojo!  Our analysts have found an Improper Privilege Management flaw identified in version 2.59.0, which resulted in the CVE-2026-16764. 

The vulnerability allows an authenticated low-privileged user to escalate their permissions to an administrative level by manipulating the is_staff parameter within the UserSerializer function, exploiting insufficient API validation.  As a consequence, an attacker can gain full administrative access to the platform, view and modify vulnerability reports across the entire organization, compromise security triage workflows, and potentially hide or manipulate critical findings. In this post, we detail the root cause of the vulnerability, its exploitation via API, the fix implemented by the DefectDojo team, and the main recommendations for risk mitigation.  Authors:  Lucas Dantas is an Information Security professional with 2 years of experience at Hakai Security, working in Application Security (AppSec), Secure Development, and Offensive Security. Specialist in Threat Modeling, with experience in Secure SDLC, Code Review, Security Maturity Assessment, Web Pentesting, and vulnerability research  Vivaldo Chagas, pentester at Hakai Security, with a background spanning application security, red team operations, and penetration testing. A native of Amazonas, Brazil, he built his career at the intersection of offensive security and attack surface analysis, relying on hands-on experience in corporate environments.  Check out the technical details and the impact of this flaw in our full article: http://yokai.hakaisecurity.io/en-cve-2026-16764-missing-validation-full-access  
Wanna try out for yourself? Come check the challenge in Hacking Club! 
https://app.hackingclub.com/training/challenges/154

    01010106
    1.2K followersView on X

Explore more