OWASP vulnerabilities
1 CVE tracked
OWASP appears in our reports in the context of both a specific tool vulnerability and guidance frameworks for LLM security. The key incident is CVE-2026-16764 found in DefectDojo 2.59.0, which allows improper privilege management through manipulation of the `is_staff` argument via the API. In parallel, their updated LLM Top 10 list retains Prompt Injection as the most critical risk, now influenced by real-world incidents. Defenders should urgently patch DefectDojo instances and review internal LLM applications against the latest OWASP guidance, focusing on Prompt Injection and Sensitive Information Disclosure risks.
Azərbaycanca: OWASP təşkilatı hesabatlarımızda həm spesifik alət zəifliyi, həm də LLM təhlükəsizliyinə dair təlimatverici çərçivələr kontekstində görünür. Əsas hadisə DefectDojo 2.59.0-da aşkarlanan CVE-2026-16764 zəifliyidir ki, bu da API vasitəsilə `is_staff` arqumentinin manipulyasiyası ilə düzgün olmayan imtiyaz idarəetməsinə səbəb olur. Paralel olaraq, təşkilatın yenilənmiş LLM Top 10 siyahısı `Prompt Injection` hücumlarını ən kritik risk kimi qoruyub saxlayır. Müdafiəçilər DefectDojo instansiyalarını təcili yeniləməli və qurumdaxili LLM tətbiqlərini OWASP-ın ən son təlimatlarına uyğun olaraq `Prompt Injection` və həssas məlumat sızması risklərinə qarşı nəzərdən keçirməlidir.
This vendor's CVEs1
This hub is built from skopnix's own reporting on OWASP: the overview is AI-written from that coverage and every CVE links to its grounded explainer. KEV status comes from CISA's Known Exploited Vulnerabilities catalog and EPSS from FIRST — vendor, version and score details are never invented.