SxDevOps 1.0/1.1 Privilege Escalation via UserSerializer update
CVE-2026-93968 Published on September 20, 2026

aiyiyi121 SxDevOps UserSerializer serializers.py update privileges management
A vulnerability was determined in aiyiyi121 SxDevOps 1.0/1.1. This affects the function update of the file backend/rbac/serializers.py of the component UserSerializer. Executing a manipulation can lead to improper privilege management. The attack can be executed remotely. This patch is called 2b4bf8585c3e731e7a8af30801ea46680bc783f9. It is best practice to apply a patch to resolve this issue. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.

NVD

Timeline

Advisory disclosed

VulDB entry created

VulDB entry last update

Weakness Types

Improper Privilege Management

The software does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Incorrect Privilege Assignment

A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.


Products Associated with CVE-2026-93968

Want to know whenever a new CVE is published for Aiyiyi121 Sxdevops? stack.watch will email you.

 

Affected Versions

aiyiyi121 SxDevOps: