Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2026-16764 — Python exploit for CVE-2026-16764, a privilege escalation in OWASP DefectDojo where an is_staff REST API bypass lets a low-privileged user gain superuser access. | Kitploit
Tools/GitHubGitHub/hakaioffsec/cve-2026-16764
Authentication & AuthorizationPrivilege EscalationVulnerability AnalysisExploitationWeb Application ExploitationPenetration TestingLearning & EducationRed TeamingAPI Security
GitHubhakaioffsec/cve-2026-16764

CVE-2026-16764

Python exploit for CVE-2026-16764, a privilege escalation in OWASP DefectDojo where an is_staff REST API bypass lets a low-privileged user gain superuser access.

18 days agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share
View Repository

CVE-2026-16764

Privilege Escalation in OWASP DefectDojo via is_staff API bypass.

Summary

A user with only auth.change_user permission can escalate to superuser in two steps:

  1. Set is_staff=true on their own account via REST API (validation only blocks is_superuser)
  2. Access Django Admin and check is_superuser checkbox

Affected Version

  • 2.59.0

Fixed Versions

  • 2.58.3, 2.58.4, 3.0.0+

CVSS

7.8 (High) - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Usage

python3 CVE-2026-16764-exploit.py -u http://target:8080 -U username -P password

Disclaimer

This tool is for educational and research purposes only. Use it only on systems you own or have explicit permission to test. The author is not responsible for any misuse or damage caused by this program.

QuimeraX Intelligence

QuimeraX Intelligence is an advanced EASM and Cyber Threat Intelligence platform specializing in identifying critical vulnerabilities in complex systems. The platform proactively monitors, detects, and alerts clients about security threats, ensuring transparency and rapid response to potential risks. Clients receive immediate notifications and comprehensive reports if their systems are found vulnerable, enabling them to take protective action. learn more

Hakai Security

Hakai Security is a cybersecurity company founded by security professionals, committed to technical excellence. We offer tailored security solutions including advanced penetration testing, realistic Red Team simulations, and secure development practices to proactively protect our clients' assets from evolving cyber threats.

Hacking Club

Hacking Club is the training platform where you learn cybersecurity through hands-on lessons, labs, and challenges created by experts working in our security consulting firm: straight from the battlefield to your training. Practice the vulnerability presented in this repository by the hacking club! learn more

References

  • GHSA-w2j3-x3j3-mm43
  • Fix PR #14952
Download Tool