CVE-2026-93970
Received Received - Intake

Hard-Coded Credentials in aiyiyi121 SxDevOps

Vulnerability report for CVE-2026-93970, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-20

Last updated on: 2026-09-20

Assigner: VulDB

Description

A security flaw has been discovered in aiyiyi121 SxDevOps 1.0/1.1. This issue affects some unknown processing of the file backend/sxdevops/settings.py of the component Settings Handler. The manipulation results in hard-coded credentials. The attack may be performed from remote. The patch is identified as 2b4bf8585c3e731e7a8af30801ea46680bc783f9. Applying a patch is advised to resolve this issue. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-20
Last Modified
2026-09-20
Generated
2026-09-20
AI Q&A
2026-09-20
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 3 associated CPEs
Vendor Product Version / Range
aiyiyi121 sxdevops 1.0
aiyiyi121 sxdevops 1.1
aiyiyi121 sxdevops to 1.1 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-798 The product contains hard-coded credentials, such as a password or cryptographic key.
CWE-259 The product contains a hard-coded password, which it uses for its own inbound authentication or for outbound communication to external components.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a security flaw in aiyiyi121 SxDevOps versions 1.0 and 1.1. It involves hard-coded credentials in the backend/sxdevops/settings.py file due to improper handling of settings. Attackers can exploit this remotely to gain unauthorized access.

Impact Analysis

The vulnerability allows remote attackers to access systems or data due to hard-coded credentials. This could lead to data breaches, unauthorized modifications, or service disruptions. The CVSS scores indicate a high severity with potential for confidentiality, integrity, and availability impacts.

Compliance Impact

This vulnerability could violate compliance requirements under GDPR and HIPAA by exposing sensitive data due to unauthorized access. Hard-coded credentials are a security risk that may lead to data breaches, resulting in legal penalties and reputational damage.

Mitigation Strategies

Apply the patch identified as 2b4bf8585c3e731e7a8af30801ea46680bc783f9 to resolve the hard-coded credentials issue in the Settings Handler component.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-93970. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart