CVE-2026-93968: SxDevOps Privilege Escalation (CVSS 3.8)
CVE-2026-93968 is a low-severity vulnerability rated 3.8/10 on the CVSS scale . A vulnerability was determined in aiyiyi121 SxDevOps 1.0/1.1. This affects the function update of the file backend/rbac/serializers.py of the component UserSerializer .
A vulnerability was determined in aiyiyi121 SxDevOps 1.0/1.1. This affects the function update of the file backend/rbac/serializers.py of the component UserSerializer. Executing a manipulation can lead to improper privilege management. The attack can be executed remotely. This patch is called 2b4bf8585c3e731e7a8af30801ea46680bc783f9. It is best practice to apply a patch to resolve this issue. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:L
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:L/E:X/RL:O/RC:C
Source: CNA advisory (CVE.org). NVD analysis pending.
Frequently Asked Questions
How Strix found a critical auth bypass in etcd Strix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
Autonomous Pentesting AI agents that find and validate exploitable vulnerabilities like this one across your applications.
PR Reviews Pentest every pull request so vulnerable code is caught before it ships to production.
AI Penetration Testing How AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
CVE-2026-93962 A weakness has been identified in Kamailio up to 5.8.8/6.0.7… 8.3
CVE-2026-93963 A security vulnerability has been detected in itsourcecode L… 6.3
CVE-2026-93964 A vulnerability was detected in NginxProxyManager nginx-prox… 5.3
CVE-2026-93965 A flaw has been found in aiyiyi121 SxDevOps 1.0/1.1. Affecte… 6.6
CVE-2026-93966 A vulnerability has been found in aiyiyi121 SxDevOps 1.0/1.1… 4.7
CVE-2026-93967 A vulnerability was found in aiyiyi121 SxDevOps 1.0/1.1. Aff… 5.5
CVE-2026-93969 A vulnerability was identified in aiyiyi121 SxDevOps 1.0/1.1… 7.3
CVE-2026-9397 A weakness has been identified in Besen BS20 EV Charging Sta… 8.2
CVE-2026-93970 A security flaw has been discovered in aiyiyi121 SxDevOps 1.… 7.3
CVE-2026-93971 A weakness has been identified in aiyiyi121 SxDevOps 1.0/1.1… 5.3
CVE-2026-93972 A security vulnerability has been detected in SourceCodester… 7.3
CVE-2026-9398 A security vulnerability has been detected in Besen BS20 EV … 3.1
Are you affected by CVE-2026-93968 ?
Run a free Strix scan to check your systems for this vulnerability.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
