Hard-Coded Credentials in aiiyi121 SxDevOps 1.01.1 rbac/services.py
CVE-2026-93969 Published on September 20, 2026
aiyiyi121 SxDevOps services.py ensure_default_superuser hard-coded credentials
A vulnerability was identified in aiyiyi121 SxDevOps 1.0/1.1. This vulnerability affects the function ensure_default_superuser of the file rbac/services.py. The manipulation leads to hard-coded credentials. The attack is possible to be carried out remotely. The identifier of the patch is 2b4bf8585c3e731e7a8af30801ea46680bc783f9. It is recommended to apply a patch to fix this issue. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.
Timeline
Advisory disclosed
VulDB entry created
VulDB entry last update
Weakness Types
Use of Hard-coded Credentials
The software contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data.
Use of Hard-coded Password
The software contains a hard-coded password, which it uses for its own inbound authentication or for outbound communication to external components.
Products Associated with CVE-2026-93969
Want to know whenever a new CVE is published for Aiyiyi121 Sxdevops? stack.watch will email you.
Affected Versions
aiyiyi121 SxDevOps:- Version 1.0 is affected.
- Version 1.1 is affected.