Command Injection Vulnerability in aaPanel BaoTa
CVE-2026-101008
Key Information:
Badges
What is CVE-2026-101008?
A critical command injection vulnerability exists in the merge_split_file function within the File Merge Handler of aaPanel BaoTa up to version 11.8.0. By manipulating the argument split_file_path, an attacker can execute arbitrary commands on the server remotely. This vulnerability has been publicly disclosed and poses significant risk to users of the affected versions. Despite early notification, the vendor has not responded to the issue, highlighting the necessity for users to assess their exposure and apply mitigations promptly.
Affected Version(s)
BaoTa 11.0
BaoTa 11.1
BaoTa 11.2
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
