Junglewise Threat Intelligence

CVE-2026-93970: aiyiyi121 SxDevOps hard-coded credentials in settings

CVE-2026-93970 · Severity: high · CVSS 7.3 · Published 2026-09-20

Technologies: Aiyiyi121 SxDevOps. Vendors: Aiyiyi121.

Executive brief

SxDevOps is an open-source DevOps automation platform that manages infrastructure and operations workflows. A hard-coded credential vulnerability in the Settings Handler component could allow remote attackers to gain unauthorized access to the platform without authentication. An attacker could use these fixed credentials to execute arbitrary operations, access sensitive data, or compromise the entire DevOps infrastructure managed by the platform.

Technical details

The vulnerability exists in backend/sxdevops/settings.py where hard-coded credentials are embedded in the component. The attack is remotely exploitable with no authentication required. An attacker can leverage these credentials to bypass authentication mechanisms and gain unauthorized access to the DevOps platform. A patch was released on 2026-09-06 (commit 2b4bf85) that replaces hard-coded passwords with environment variable-driven configuration.

Affected products

  • aiyiyi121 SxDevOps 1.0, 1.1

Timeline

  • 2026-09-20: disclosed: CVE-2026-93970 published on NVD
  • 2026-09-06: patched: Patch commit 2b4bf8585c3e731e7a8af30801ea46680bc783f9 released

References

Related threats