CVE-2026-93971: SxDevOps Information Disclosure (CVSS 5.3)
CVE-2026-93971 is a medium-severity vulnerability rated 5.3/10 on the CVSS scale . A weakness has been identified in aiyiyi121 SxDevOps 1.0/1.1. Impacted is an unknown function of the file backend/sxdevops/settings.py .
A weakness has been identified in aiyiyi121 SxDevOps 1.0/1.1. Impacted is an unknown function of the file backend/sxdevops/settings.py. This manipulation causes information disclosure. It is possible to initiate the attack remotely. Patch name: 2b4bf8585c3e731e7a8af30801ea46680bc783f9. It is suggested to install a patch to address this issue. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:X/RL:O/RC:C
Source: CNA advisory (CVE.org). NVD analysis pending.
Frequently Asked Questions
Uncovering a hidden BOLA in Appsmith's snapshot logic Strix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
Autonomous Pentesting AI agents that find and validate exploitable vulnerabilities like this one across your applications.
PR Reviews Pentest every pull request so vulnerable code is caught before it ships to production.
AI Penetration Testing How AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
CVE-2026-93966 A vulnerability has been found in aiyiyi121 SxDevOps 1.0/1.1… 4.7
CVE-2026-93967 A vulnerability was found in aiyiyi121 SxDevOps 1.0/1.1. Aff… 5.5
CVE-2026-93968 A vulnerability was determined in aiyiyi121 SxDevOps 1.0/1.1… 3.8
CVE-2026-93969 A vulnerability was identified in aiyiyi121 SxDevOps 1.0/1.1… 7.3
CVE-2026-9397 A weakness has been identified in Besen BS20 EV Charging Sta… 8.2
CVE-2026-93970 A security flaw has been discovered in aiyiyi121 SxDevOps 1.… 7.3
CVE-2026-93972 A security vulnerability has been detected in SourceCodester… 7.3
CVE-2026-9398 A security vulnerability has been detected in Besen BS20 EV … 3.1
CVE-2026-93981 hono before 4.13.7 fails to HTML-escape plain strings render… 4.7
CVE-2026-93982 OpenPanel through commit bad75bdd writes Model Context Proto… 3.3
CVE-2026-93983 OpenPanel through commit bad75bdd fails to escape property k… 5
CVE-2026-93984 OpenPanel tracking API through commit bad75bddc74d12d36cfb84… 5.3
Are you affected by CVE-2026-93971 ?
Run a free Strix scan to check your systems for this vulnerability.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
