CVE detail
CVE-2026-16764
A vulnerability was identified in OWASP DefectDojo 2.59.0. This issue affects the function UserSerializer of the file dojo/api_v2/serializers.py of the component API/Web. Such manipulation of the argument is_staff leads to improper privilege management. The attack may be performed from remote. The exploit is publicly available and might be used. Upgrading to version 2.58.3 and 3.0.0 is capable of addressing this issue. The name of the patch is 68a272f299d096249fd3ba9c2676bf69012857bf. It is advisable to upgrade the affected component. 2.59.0 was not intended to be released and has been removed.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 22.0 · diversity 6.5 · KEV 0.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 8
- within the 30d window
- Peak daily
- 8
- highest bucket
Evidence
Source links by recency
8 source links · newest first
- https://vuldb.com/vuln/382629/ctivuldb.com
No excerpt available.
Exploitvuldb.comJul 23, 2026, 10:16 PM - https://vuldb.com/vuln/382629vuldb.com
No excerpt available.
Exploitvuldb.comJul 23, 2026, 10:16 PM - https://vuldb.com/submit/861317vuldb.com
No excerpt available.
Exploitvuldb.comJul 23, 2026, 10:16 PM - https://vuldb.com/cve/CVE-2026-16764vuldb.com
No excerpt available.
Exploitvuldb.comJul 23, 2026, 10:16 PM No excerpt available.
Exploitgithub.comJul 23, 2026, 10:16 PMNo excerpt available.
Exploitgithub.comJul 23, 2026, 10:16 PMNo excerpt available.
Exploitgithub.comJul 23, 2026, 10:16 PM- https://github.com/DefectDojo/django-DefectDojo/commit/68a272f299d096249fd3ba9c2676bf69012857bfgithub.com
No excerpt available.
Exploitgithub.comJul 23, 2026, 10:16 PM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2026-14719CVSS 5.5 · Medium
A flaw has been found in SourceCodester Onlne Examination & Learning Management System 1.0. The impacted element is an unknown function of the file register.php of the component R…
- CVE-2026-12289CVSS 8.8 · High
Privilege escalation in the Graphics: WebRender component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firefox ESR 115.37, Thunderbird 152, and Thunderbird 14…
- CVE-2026-12217CVSS 7.1 · High
A security vulnerability has been detected in DVDFab Virtual Drive 2.0.0.5. Impacted is an unknown function in the library dvdfabio.sys of the component Signed Kernel Driver. The…
- CVE-2026-10217CVSS 2.1 · Low
A flaw has been found in nextlevelbuilder GoClaw up to 3.11.3. The impacted element is the function handleSave of the file internal/http/tts_config.go of the component RoleAdmin G…
- CVE-2026-5141CVSS 8.8 · High
Improper Privilege Management, Improper Access Control, Incorrect privilege assignment vulnerability in TUBITAK BILGEM Software Technologies Research Institute Pardus Software Cen…
- CVE-2026-6750CVSS 8.8 · High
Privilege escalation in the Graphics: WebRender component. This vulnerability was fixed in Firefox 150, Firefox ESR 115.35, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 14…