CVE-2026-93970 Details
Description
A security flaw has been discovered in aiyiyi121 SxDevOps 1.0/1.1. This issue affects some unknown processing of the file backend/sxdevops/settings.py of the component Settings Handler. The manipulation results in hard-coded credentials. The attack may be performed from remote. The patch is identified as 2b4bf8585c3e731e7a8af30801ea46680bc783f9. Applying a patch is advised to resolve this issue. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.
A vulnerability exists in SxDevOps versions 1.0 and 1.1, specifically within the Settings Handler component. The issue arises from an undisclosed processing in the file 'backend/sxdevops/settings.py', leading to the introduction of hard-coded credentials. This vulnerability can be exploited remotely.
Users are advised to update to the patched version of SxDevOps, which is available on the project's GitHub repository.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 20, 2026CISA-ADP
Assessed Sep 23, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/aiyiyi121/sxdevops/ | [email protected] | ProductSource CodeVendor |
| https://github.com/aiyiyi121/sxdevops/commit/2b4bf8585c3e731e7a8af30801ea46680bc783f9 | [email protected] | Source CodeVendor |
| https://github.com/aiyiyi121/sxdevops/issues/16 | [email protected] | BundleExploitIssue TrackingRemedyTechnical AnalysisVendor |
| https://vuldb.com/cve/CVE-2026-93970 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/submit/944385 | [email protected] | Issue TrackingPermission Required |
| https://vuldb.com/vuln/407929 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/vuln/407929/cti | [email protected] | Content Wall |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-259 | Use of Hard-coded Password | [email protected] |
| CWE-798 | Use of Hard-coded Credentials | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| aiyiyi121 SxDevOps | 1.0 1.1 |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 23, 2026 | CVE Modified | CISA-ADP |
| Sep 20, 2026 | New CVE Received | [email protected] |
Volerion