Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Sun, 20 Sep 2026 06:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability was determined in aiyiyi121 SxDevOps 1.0/1.1. This affects the function update of the file backend/rbac/serializers.py of the component UserSerializer. Executing a manipulation can lead to improper privilege management. The attack can be executed remotely. This patch is called 2b4bf8585c3e731e7a8af30801ea46680bc783f9. It is best practice to apply a patch to resolve this issue. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product. | |
| Title | aiyiyi121 SxDevOps UserSerializer serializers.py update privileges management | |
| First Time appeared |
Aiyiyi121
Aiyiyi121 sxdevops |
|
| Weaknesses | CWE-266 CWE-269 |
|
| CPEs | cpe:2.3:a:aiyiyi121:sxdevops:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Aiyiyi121
Aiyiyi121 sxdevops |
|
| References |
|
|
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-09-20T06:30:13.438Z
Reserved: 2026-09-19T10:14:54.728Z
Link: CVE-2026-93968
No data.
Status : Received
Published: 2026-09-20T07:16:52.100
Modified: 2026-09-20T07:16:52.100
Link: CVE-2026-93968
No data.
OpenCVE Enrichment
Updated: 2026-09-20T08:30:16Z