Description
A vulnerability was determined in aiyiyi121 SxDevOps 1.0/1.1. This affects the function update of the file backend/rbac/serializers.py of the component UserSerializer. Executing a manipulation can lead to improper privilege management. The attack can be executed remotely. This patch is called 2b4bf8585c3e731e7a8af30801ea46680bc783f9. It is best practice to apply a patch to resolve this issue. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.
Published: 2026-09-20
Score: 5.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Privilege Escalation
Action: Patch
AI Analysis

Impact

The reported flaw lies in the update method of the UserSerializer class in the backend/rbac/serializers.py module of SxDevOps 1.0 and 1.1. The code incorrectly handles privilege assignments, allowing an attacker to manipulate user roles or permission levels beyond their intended scope. This flaw results in improper privilege management, effectively enabling a privileged escalation that could expose sensitive data or compromise system integrity.

Affected Systems

SxDevOps, an open-source DevOps platform maintained by aiyiyi121, is affected by versions 1.0 and 1.1.

Risk and Exploitability

The CVSS severity is 5.1, indicating a medium risk that does not include denial of service or remote code execution but still requires immediate attention. Because the EPSS score is not available and the vulnerability is not listed in CISA KEV, the likelihood of exploitation remains uncertain; however, the remote attack capability makes it a typical target for adversaries seeking to increase privileges. The lack of a CVSS vector for attack complexity or privileges suggests that exploitation may not require advanced skills, further elevating the risk profile for unpatched deployments.

Generated by OpenCVE AI on September 20, 2026 at 08:30 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the patch committed in 2b4bf8585c3e731e7a8af30801ea46680bc783f9 to update the UserSerializer code.
  • Upgrade SxDevOps to a patched release that includes the fix.
  • If upgrading is not immediately possible, restrict API access to the update operation by enforcing authentication and verifying that the caller possesses the necessary permission to modify user roles.
  • Monitor authentication logs for unexpected role changes as a post‑detected response.

Generated by OpenCVE AI on September 20, 2026 at 08:30 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 20 Sep 2026 06:45:00 +0000

Type Values Removed Values Added
Description A vulnerability was determined in aiyiyi121 SxDevOps 1.0/1.1. This affects the function update of the file backend/rbac/serializers.py of the component UserSerializer. Executing a manipulation can lead to improper privilege management. The attack can be executed remotely. This patch is called 2b4bf8585c3e731e7a8af30801ea46680bc783f9. It is best practice to apply a patch to resolve this issue. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.
Title aiyiyi121 SxDevOps UserSerializer serializers.py update privileges management
First Time appeared Aiyiyi121
Aiyiyi121 sxdevops
Weaknesses CWE-266
CWE-269
CPEs cpe:2.3:a:aiyiyi121:sxdevops:*:*:*:*:*:*:*:*
Vendors & Products Aiyiyi121
Aiyiyi121 sxdevops
References
Metrics cvssV2_0

{'score': 4.7, 'vector': 'AV:N/AC:L/Au:M/C:N/I:P/A:P/E:ND/RL:OF/RC:C'}

cvssV3_0

{'score': 3.8, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:L/E:X/RL:O/RC:C'}

cvssV3_1

{'score': 3.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:L/E:X/RL:O/RC:C'}

cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X'}


Subscriptions

Aiyiyi121 Sxdevops
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-21T18:09:00.948Z

Reserved: 2026-09-19T10:14:54.728Z

Link: CVE-2026-93968

cve-icon Vulnrichment

Updated: 2026-09-21T18:08:57.277Z

cve-icon NVD

Status : Deferred

Published: 2026-09-20T07:16:52.100

Modified: 2026-09-21T19:17:18.890

Link: CVE-2026-93968

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T10:02:46Z

Weaknesses
  • CWE-266

    Incorrect Privilege Assignment

  • CWE-269

    Improper Privilege Management