CVE-2026-93968 Details
Description
A vulnerability was determined in aiyiyi121 SxDevOps 1.0/1.1. This affects the function update of the file backend/rbac/serializers.py of the component UserSerializer. Executing a manipulation can lead to improper privilege management. The attack can be executed remotely. This patch is called 2b4bf8585c3e731e7a8af30801ea46680bc783f9. It is best practice to apply a patch to resolve this issue. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.
A vulnerability allowing improper privilege management has been identified in SxDevOps versions 1.0 and 1.1. The issue resides in the UserSerializer component, specifically within the update function of the file backend/rbac/serializers.py. This vulnerability can be exploited remotely, allowing users to manipulate privileges by modifying certain user attributes.
The vulnerability has been addressed by updating the UserSerializer to include 'is_superuser', 'is_staff', and 'is_active' in the read-only fields, preventing unauthorized modifications. It is recommended to apply this patch and ensure that the serializer is not used in a way that bypasses the updated validation.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 20, 2026CISA-ADP
Assessed Sep 21, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/aiyiyi121/sxdevops/ | [email protected] | Source CodeVendor |
| https://github.com/aiyiyi121/sxdevops/commit/2b4bf8585c3e731e7a8af30801ea46680bc783f9 | [email protected] | Source CodeVendor |
| https://github.com/aiyiyi121/sxdevops/issues/16 | [email protected] | AdvisoryBundleExploitIssue TrackingRemedyVendor |
| https://vuldb.com/cve/CVE-2026-93968 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/submit/944383 | [email protected] | Issue TrackingPermission Required |
| https://vuldb.com/vuln/407927 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/vuln/407927/cti | [email protected] | Content Wall |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-266 | Incorrect Privilege Assignment | [email protected] |
| CWE-269 | Improper Privilege Management | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| aiyiyi121 SxDevOps | >= 1.0, < 1.2 |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 21, 2026 | CVE Modified | CISA-ADP |
| Sep 20, 2026 | New CVE Received | [email protected] |
Volerion