Description
A security flaw has been discovered in aiyiyi121 SxDevOps 1.0/1.1. This issue affects some unknown processing of the file backend/sxdevops/settings.py of the component Settings Handler. The manipulation results in hard-coded credentials. The attack may be performed from remote. The patch is identified as 2b4bf8585c3e731e7a8af30801ea46680bc783f9. Applying a patch is advised to resolve this issue. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.
Published: 2026-09-20
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Credential Exposure
Action: Apply Patch
AI Analysis

Impact

The vulnerability is a hard‑coded credential issue in the Settings Handler of SxDevOps. The manipulation of backend/sxdevops/settings.py exposes sensitive authentication information, which an attacker can read or override. This flaw aligns with CWE‑259 (Hard‑coded Password) and CWE‑798 (Using Hard‑coded Secrets). Because credentials can be exposed or altered, an attacker may gain unauthorized access to the system or elevate privileges.

Affected Systems

The affected product is aiyiyi121:SxDevOps, specifically versions 1.0 and 1.1. No other vendor or product versions are listed as impacted.

Risk and Exploitability

The CVSS score of 6.9 indicates a moderate risk. EPSS for this vulnerability is not available, so the precise likelihood of exploitation cannot be quantified. The vendor notes that the attack may be performed from remote, suggesting that legitimate remote users could trigger the flaw. The issue is not listed in the CISA KEV catalog, implying no known deployed exploits in the wild yet, but the presence of hard‑coded credentials remains a critical concern.

Generated by OpenCVE AI on September 20, 2026 at 08:53 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the vendor’s patch identified by commit 2b4bf8585c3e731e7a8af30801ea46680bc783f9 to eliminate hard‑coded credentials in settings.py.
  • After applying the patch, verify that no default usernames or passwords remain in the configuration and replace any residual secrets with secure credential management practices such as environment variables or a vault service.
  • If an immediate patch cannot be applied, restrict remote access to the Settings Handler or enforce strict authentication checks before allowing any configuration changes.

Generated by OpenCVE AI on September 20, 2026 at 08:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 23 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 20 Sep 2026 07:30:00 +0000

Type Values Removed Values Added
Description A security flaw has been discovered in aiyiyi121 SxDevOps 1.0/1.1. This issue affects some unknown processing of the file backend/sxdevops/settings.py of the component Settings Handler. The manipulation results in hard-coded credentials. The attack may be performed from remote. The patch is identified as 2b4bf8585c3e731e7a8af30801ea46680bc783f9. Applying a patch is advised to resolve this issue. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.
Title aiyiyi121 SxDevOps Settings settings.py hard-coded credentials
First Time appeared Aiyiyi121
Aiyiyi121 sxdevops
Weaknesses CWE-259
CWE-798
CPEs cpe:2.3:a:aiyiyi121:sxdevops:*:*:*:*:*:*:*:*
Vendors & Products Aiyiyi121
Aiyiyi121 sxdevops
References
Metrics cvssV2_0

{'score': 7.5, 'vector': 'AV:N/AC:L/Au:N/C:P/I:P/A:P/E:ND/RL:OF/RC:C'}

cvssV3_0

{'score': 7.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:X/RL:O/RC:C'}

cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:X/RL:O/RC:C'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X'}


Subscriptions

Aiyiyi121 Sxdevops
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-23T18:17:06.871Z

Reserved: 2026-09-19T10:15:01.679Z

Link: CVE-2026-93970

cve-icon Vulnrichment

Updated: 2026-09-23T18:17:03.722Z

cve-icon NVD

Status : Deferred

Published: 2026-09-20T08:16:51.080

Modified: 2026-09-23T19:19:46.890

Link: CVE-2026-93970

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T09:00:13Z

Weaknesses
  • CWE-259

    Use of Hard-coded Password

  • CWE-798

    Use of Hard-coded Credentials