SxDevOps 1.0/1.1 Privilege Escalation via UserSerializer update
CVE-2026-93968 Published on September 20, 2026
aiyiyi121 SxDevOps UserSerializer serializers.py update privileges management
A vulnerability was determined in aiyiyi121 SxDevOps 1.0/1.1. This affects the function update of the file backend/rbac/serializers.py of the component UserSerializer. Executing a manipulation can lead to improper privilege management. The attack can be executed remotely. This patch is called 2b4bf8585c3e731e7a8af30801ea46680bc783f9. It is best practice to apply a patch to resolve this issue. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.
Timeline
Advisory disclosed
VulDB entry created
VulDB entry last update
Weakness Types
Improper Privilege Management
The software does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.
Incorrect Privilege Assignment
A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.
Products Associated with CVE-2026-93968
Want to know whenever a new CVE is published for Aiyiyi121 Sxdevops? stack.watch will email you.
Affected Versions
aiyiyi121 SxDevOps:- Version 1.0 is affected.
- Version 1.1 is affected.