Skip to content
CVE Alert: CVE-2026-93970 – aiyiyi121

CVE Alert: CVE-2026-93970 – aiyiyi121

Redpacketsecurity admin September 20, 2026

A security flaw has been discovered in aiyiyi121 SxDevOps 1.0/1.1. This issue affects some unknown processing of the file backend/sxdevops/settings.py of the component Settings Handler. The manipulation results in hard-coded credentials. The attack may be performed from remote. The patch is identified as 2b4bf8585c3e731e7a8af30801ea46680bc783f9. Applying a patch is advised to resolve this issue. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.

**Risk verdict:** Treat as a high-priority remediation for internet-facing deployments, although the absence of confirmed exploitation, KEV status, and EPSS data leaves active-threat urgency uncertain.

**Why this matters:** Embedded credentials can provide a reusable foothold into application administration, source repositories, databases, or deployment infrastructure, depending on their privileges and reuse. The realistic business impact ranges from unauthorised data access and tampering to service disruption and compromise of downstream development or production systems.

**Most likely attack path:** The network-reachable, low-complexity, unauthenticated, non-interactive profile suggests an attacker may be able to reach the affected handler directly without user involvement. Scope is unchanged in the scoring, but stolen credentials could still enable lateral movement if they are valid elsewhere or grant access to connected DevOps services; the exact endpoint and credential permissions remain unclear.

**Who is most exposed:** Organisations running SxDevOps as a remotely accessible service, particularly those exposing development tooling or management interfaces to the internet, are most at risk. Source deployments that retain the affected settings file or reuse its credentials warrant immediate review.

repositories, images, and hosts for the affected settings file and credential-like constants.

Review authentication logs for unexpected use of discovered accounts or keys.

Hunt for access to DevOps APIs, repositories, build agents, and deployment targets from unusual sources.

Check for anomalous outbound connections or new administrative activity.

Mitigation and prioritisation:

Upgrade or apply the identified fix promptly; treat as emergency change for internet-facing systems.

Rotate all embedded credentials and invalidate potentially exposed tokens, including reused secrets.

Restrict administrative interfaces to VPNs or allow-listed networks and enforce MFA upstream.

Test whether credentials provide access beyond SxDevOps, then review and reduce privileges.

No KEV, SSVC exploitation state, EPSS score, or PoC indicator is supplied; validate these before downgrading urgency.

A considerable amount of time and effort goes into maintaining this website, creating backend automation and creating new features and content for you to make actionable intelligence decisions. Everyone that supports the site helps enable new functionality.

If you like the site, please support us on Patreon or Buy Me A Coffee using the buttons below.

Extracted Entities