CVE-2026-93968: aiyiyi121 SxDevOps UserSerializer serializers.py update privileges management
A vulnerability was determined in aiyiyi121 SxDevOps 1.0/1.1. This affects the function update of the file backend/rbac/serializers.py of the component UserSerializer. Executing a manipulation can lead to improper privilege management. The attack can be executed remotely. This patch is called 2b4bf8585c3e731e7a8af30801ea46680bc783f9. It is best practice to apply a patch to resolve this issue. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
aiyiyi121 SxDevOpsto a version that resolves this vulnerability.Patch 2b4bf8585c3e731e7a8af30801ea46680bc783f9
Event History
Frequently Asked Questions
Can an unauthenticated remote attacker exploit this issue?
The attack can be performed remotely, but the provided CVSS vector indicates that the attacker must already have high privileges. No user interaction is required.
What should be deployed to remediate the issue?
Apply the vendor patch identified as commit 2b4bf8585c3e731e7a8af30801ea46680bc783f9. The vendor reportedly released a fixed version, but no fixed version number is provided.
Is a temporary mitigation documented if patching is delayed?
No alternative workaround or compensating control is documented in the provided information. Applying the patch is the stated remediation.