Hard-Coded Credentials in aiiyi121 SxDevOps 1.01.1 rbac/services.py
CVE-2026-93969 Published on September 20, 2026

aiyiyi121 SxDevOps services.py ensure_default_superuser hard-coded credentials
A vulnerability was identified in aiyiyi121 SxDevOps 1.0/1.1. This vulnerability affects the function ensure_default_superuser of the file rbac/services.py. The manipulation leads to hard-coded credentials. The attack is possible to be carried out remotely. The identifier of the patch is 2b4bf8585c3e731e7a8af30801ea46680bc783f9. It is recommended to apply a patch to fix this issue. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.

NVD

Timeline

Advisory disclosed

VulDB entry created

VulDB entry last update

Weakness Types

Use of Hard-coded Credentials

The software contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data.

Use of Hard-coded Password

The software contains a hard-coded password, which it uses for its own inbound authentication or for outbound communication to external components.


Products Associated with CVE-2026-93969

Want to know whenever a new CVE is published for Aiyiyi121 Sxdevops? stack.watch will email you.

 

Affected Versions

aiyiyi121 SxDevOps: