CVE-2026-93970: Hard-coded creds in aiyiyi121 SxDevOps 1.0 Settings Handler
CVE-2026-93970 Published on September 20, 2026
aiyiyi121 SxDevOps Settings settings.py hard-coded credentials
A security flaw has been discovered in aiyiyi121 SxDevOps 1.0/1.1. This issue affects some unknown processing of the file backend/sxdevops/settings.py of the component Settings Handler. The manipulation results in hard-coded credentials. The attack may be performed from remote. The patch is identified as 2b4bf8585c3e731e7a8af30801ea46680bc783f9. Applying a patch is advised to resolve this issue. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.
Timeline
Advisory disclosed
VulDB entry created
VulDB entry last update
Weakness Types
Use of Hard-coded Credentials
The software contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data.
Use of Hard-coded Password
The software contains a hard-coded password, which it uses for its own inbound authentication or for outbound communication to external components.
Products Associated with CVE-2026-93970
Want to know whenever a new CVE is published for Aiyiyi121 Sxdevops? stack.watch will email you.
Affected Versions
aiyiyi121 SxDevOps:- Version 1.0 is affected.
- Version 1.1 is affected.