CVE-2026-101008
Received Received - Intake

Command Injection in aaPanel BaoTa File Merge Handler

Vulnerability report for CVE-2026-101008, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-28

Last updated on: 2026-09-28

Assigner: VulDB

Description

A vulnerability was found in aaPanel BaoTa up to 11.8.0. Impacted is the function merge_split_file of the file /www/server/panel/class/files.py of the component File Merge Handler. Performing a manipulation of the argument split_file_path results in command injection. The attack is possible to be carried out remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-28
Last Modified
2026-09-28
Generated
2026-09-28
AI Q&A
2026-09-28
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
aapanel bao_ta to 11.8.0 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-74 The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.
CWE-77 The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a Remote Code Execution (RCE) flaw in aaPanel BaoTa up to version 11.8.0. It exists in the merge_split_file function of the files.py file. The issue is command injection via the split_file_path parameter, allowing attackers to execute arbitrary shell commands with root privileges by uploading a malicious JSON file.

Detection Guidance

Check for suspicious files in /tmp like bt_pwned_h02 or similar markers. Monitor network traffic for unexpected API calls to /www/server/panel/class/files.py with merge_split_file. Review logs for commands containing split_file_path with shell metacharacters like ;, |, or &&.

Impact Analysis

An attacker could exploit this to run malicious commands on the server with root access, potentially taking full control of the system. This could lead to data theft, system damage, or further network compromise. The attack can be performed remotely without needing local access.

Compliance Impact

This vulnerability could lead to unauthorized access and data breaches, violating GDPR and HIPAA requirements for data protection and access controls. Organizations using affected aaPanel versions may face compliance violations, legal penalties, and reputational damage.

Mitigation Strategies

Update aaPanel BaoTa to the latest version if available. Restrict access to the merge_split_file endpoint via firewall rules. Disable the vulnerable API endpoint if not required. Monitor for unauthorized file creation in /tmp and system command execution logs.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-101008. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart