Sceawere

Vulnerability Detail

CVE-2026-101008UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

aaPanel Remote Command Injection

Vulnerability Metadata

Severity
Critical
Score / CVSS
9.1
Creation Date
2h ago
Vendor
aaPanel
Product
BaoTa
Attack Type
Command Injection
Vector String
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

A vulnerability was found in aaPanel BaoTa up to 11.8.0. Impacted is the function merge_split_file of the file /www/server/panel/class/files.py of the component File Merge Handler. Performing a manipulation of the argument split_file_path results in command injection. The attack is possible to be carried out remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "9.1",
  "pubDate": "2026-09-28T07:17:20.403Z",
  "pubdate": "2026-09-28T07:17:20.403Z",
  "executiveSummary": "A critical command injection vulnerability has been identified in aaPanel BaoTa versions up to 11.8.0. The vulnerability resides within the File Merge Handler component, specifically affecting the merge_split_file function.\nAn unauthenticated remote attacker can exploit this flaw by supplying malicious input to the split_file_path argument, leading to arbitrary command execution on the host server.\nThis vulnerability carries a severe security risk as it allows for full system compromise, unauthorized data access, and potential persistence mechanisms.\nGiven that public exploit code is currently available and the vendor has not responded to disclosure attempts, the risk of exploitation is high. Organizations utilizing affected versions are at immediate risk of remote code execution (RCE) attacks.\nThe vulnerability is accessible over the network, requiring no prior authentication or administrative privileges to execute the malicious payload.",
  "technicalDetails": "The vulnerability is located in the /www/server/panel/class/files.py file within the merge_split_file function, which serves as part of the File Merge Handler component of aaPanel.\nThe root cause is an improper sanitization and validation process of user-supplied input provided to the split_file_path argument. The application fails to properly neutralize special shell characters or validate the structure of the input before passing it to system-level execution functions.\nWhen the merge_split_file function processes the split_file_path parameter, the input is concatenated directly into a shell command string. Because the application lacks sufficient input filtering or parameterization, an attacker can perform command injection by injecting shell meta-characters (such as ';', '&', or '|').\nThe attack flow begins when an attacker sends a crafted request to the endpoint responsible for invoking the merge_split_file operation. By manipulating the split_file_path argument to include a command payload, the underlying system shell interprets the injected string as part of the execution flow.\nAs this function is exposed through the panel's web interface, the attack is fully remote. Successful exploitation results in the execution of arbitrary commands with the privileges of the web server process (typically the user running the aaPanel service).\nGiven the nature of the web application, this could lead to the installation of backdoors, extraction of sensitive system configuration files, modification of database contents, or lateral movement within the compromised infrastructure.\nThe vulnerability is confirmed in all versions up to 11.8.0. As no patch has been provided by the vendor, the application remains susceptible to exploitation via public exploit vectors."
}
CVE-2026-101008: aaPanel Remote Command Injection (CRITICAL Severity, CVSS: 9.1) | Sceawere