CVE-2026-93969 is a vulnerability in aiyiyi121 SxDevOps 1.0/1.1 that affects the ensure_default_superuser function in rbac/services.py, leading to hard-coded credentials. The attack can be carried out remotely. A patch (2b4bf8585c3e731e7a8af30801ea46680bc783f9) is available to fix this issue. The vendor responded professionally and quickly released a fixed version.
A vulnerability was determined in aiyiyi121 SxDevOps 1.0/1.1. This affects the function update of the file backend/rbac/serializers.py of the component UserSerializer. Executing a manipulation can lead to improper privilege management. The attack can be executed remotely. This patch is called 2b4bf8585c3e731e7a8af30801ea46680bc783f9. It is best practice to apply a patch to resolve this issue.
A vulnerability was found in aiyiyi121 SxDevOps 1.0/1.1. Affected by this issue is the function generate_host_task of the file backend/aiops/services.py of the component Command Handler. Performing a manipulation of the argument command results in command injection. Remote exploitation of the attack is possible. The patch is named 2b4bf8585c3e731e7a8af30801ea46680bc783f9. Applying a patch is the recommend [truncated]
CVE-2026-93966 is a command injection vulnerability in the TASK_RUN_COMMAND component of aiyiyi121 SxDevOps 1.0/1.1. The vulnerability is caused by manipulation of the argument command in the function paramiko.SSHClient.exec_command of the file backend/ops/host_tasks.py. This issue can be remotely exploited. A patch, 2b4bf8585c3e731e7a8af30801ea46680bc783f9, has been released to correct this issue.
A command injection vulnerability was found in aiyiyi121 SxDevOps 1.0/1.1, specifically in the subprocess.Popen function of the backend/aiops/services.py file. This issue allows remote attackers to inject commands via manipulation of the endpoint_or_command argument. A patch (2b4bf8585c3e731e7a8af30801ea46680bc783f9) has been released to address this issue. The vulnerability has a CVSS score of 5.1, indic [truncated]