Description
A vulnerability was identified in aiyiyi121 SxDevOps 1.0/1.1. This vulnerability affects the function ensure_default_superuser of the file rbac/services.py. The manipulation leads to hard-coded credentials. The attack is possible to be carried out remotely. The identifier of the patch is 2b4bf8585c3e731e7a8af30801ea46680bc783f9. It is recommended to apply a patch to fix this issue. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.
Published: 2026-09-20
Score: 6.9 Medium
EPSS: n/a
KEV: No
Impact: Privilege Escalation
Action: Patch Immediately
AI Analysis

Impact

A vulnerability exists in SxDevOps version 1.0 and 1.1 where the function ensure_default_superuser contains hard‑coded credentials. The flaw is a credential compromise weakness that can allow an attacker to obtain privileged access, potentially gaining full control of the system.

Affected Systems

Vendors and affected products include aiyiyi121 SxDevOps versions 1.0 and 1.1. The vulnerability is present in the rbac/services.py file, and the provider has released a patch with commit 2b4bf8585c3e731e7a8af30801ea46680bc783f9.

Risk and Exploitability

The CVSS score of 6.9 indicates a medium severity. EPSS is not available, and the vulnerability is not listed in CISA KEV. The description states that remote attackers can exploit this flaw, so the attack vector is likely remote. Because the flaw involves hard‑coded credentials, a successful exploitation would lead to privilege escalation.

Generated by OpenCVE AI on September 20, 2026 at 08:29 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor’s patch (commit 2b4bf8585c3e731e7a8af30801ea46680bc783f9) or upgrade to the latest SxDevOps release.
  • Replace any remaining hard‑coded credentials with secure credential storage and enforce password complexity requirements.
  • Conduct a thorough review of authentication logic to ensure no unauthorized default users remain.

Generated by OpenCVE AI on September 20, 2026 at 08:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 07:00:00 +0000

Type Values Removed Values Added
Description A vulnerability was identified in aiyiyi121 SxDevOps 1.0/1.1. This vulnerability affects the function ensure_default_superuser of the file rbac/services.py. The manipulation leads to hard-coded credentials. The attack is possible to be carried out remotely. The identifier of the patch is 2b4bf8585c3e731e7a8af30801ea46680bc783f9. It is recommended to apply a patch to fix this issue. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.
Title aiyiyi121 SxDevOps services.py ensure_default_superuser hard-coded credentials
First Time appeared Aiyiyi121
Aiyiyi121 sxdevops
Weaknesses CWE-259
CWE-798
CPEs cpe:2.3:a:aiyiyi121:sxdevops:*:*:*:*:*:*:*:*
Vendors & Products Aiyiyi121
Aiyiyi121 sxdevops
References
Metrics cvssV2_0

{'score': 7.5, 'vector': 'AV:N/AC:L/Au:N/C:P/I:P/A:P/E:ND/RL:OF/RC:C'}

cvssV3_0

{'score': 7.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:X/RL:O/RC:C'}

cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:X/RL:O/RC:C'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X'}


Subscriptions

Aiyiyi121 Sxdevops
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-20T06:45:09.655Z

Reserved: 2026-09-19T10:14:58.229Z

Link: CVE-2026-93969

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-20T07:16:52.290

Modified: 2026-09-20T07:16:52.290

Link: CVE-2026-93969

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T08:30:16Z

Weaknesses
  • CWE-259

    Use of Hard-coded Password

  • CWE-798

    Use of Hard-coded Credentials