Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 23 Jul 2026 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability was identified in OWASP DefectDojo 2.59.0. This issue affects the function UserSerializer of the file dojo/api_v2/serializers.py of the component API/Web. Such manipulation of the argument is_staff leads to improper privilege management. The attack may be performed from remote. The exploit is publicly available and might be used. Upgrading to version 2.58.3 and 3.0.0 is capable of addressing this issue. The name of the patch is 68a272f299d096249fd3ba9c2676bf69012857bf. It is advisable to upgrade the affected component. 2.59.0 was not intended to be released and has been removed. | |
| Title | OWASP DefectDojo API/Web serializers.py UserSerializer privileges management | |
| First Time appeared |
Owasp
Owasp defectdojo |
|
| Weaknesses | CWE-266 CWE-269 |
|
| CPEs | cpe:2.3:a:owasp:defectdojo:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Owasp
Owasp defectdojo |
|
| References |
|
|
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-07-23T21:30:11.529Z
Reserved: 2026-07-23T14:12:06.687Z
Link: CVE-2026-16764
No data.
No data.
No data.
OpenCVE Enrichment
No data.