Owasp · Defectdojo · CVE-2026-16764
**Name of the Vulnerable Software and Affected Versions**
OWASP DefectDojo version 2.59.0
**Description**
Improper privilege management occurs in the API/Web component within the `UserSerializer()` function located in the `dojo/api v2/serializers.py` file. A remote attacker can manipulate the `is staff` argument to gain unauthorized privileges.
**Recommendations**
Upgrade to version 2.58.3 or 3.0.0.