Local File Inclusion Vulnerability in aaPanel by aaPanel Team
CVE-2026-29858

7.5HIGH

Key Information:

Vendor

aaPanel

Status
Vendor
CVE Published:
18 March 2026

What is CVE-2026-29858?

A local file inclusion vulnerability has been identified in aaPanel version 7.57.0, stemming from inadequate validation of file paths. This flaw permits malicious actors to exploit the system and potentially access sensitive information, risking the integrity of user data. It is crucial for users of aaPanel to address this vulnerability to safeguard their environments.

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.