CVE-2026-16764 | OWASP DefectDojo 2.59.0 API/Web serializers.py UserSerializer is_staff privileges management (GHSA-w2j3-x3j3-mm43)
A vulnerability categorized as critical has been discovered in OWASP DefectDojo 2.59.0. This issue affects the function UserSerializer of the file dojo/api_v2/serializers.py of the component API/Web. Such manipulation of the argument is_staff leads to improper privilege management.
This vulnerability is listed as CVE-2026-16764. The attack may be performed from remote. In addition, an exploit is available.
It is advisable to upgrade the affected component.
2.59.0 was not intended to be released and has been removed.