Sceawere
Vulnerability Detail
CVE-2026-101009UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
aaPanel OS Command Injection Vulnerability
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 8.4
- Creation Date
- 2h ago
- Vendor
- aaPanel
- Product
- BaoTa
- Attack Type
- OS Command Injection
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
A vulnerability was determined in aaPanel BaoTa up to 11.8.0. The affected element is the function panelTask.bt_task._unzip of the file /www/server/panel/class/panelTask.py of the component Unzip Handler. Executing a manipulation of the argument Password can lead to os command injection. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "8.4",
"pubDate": "2026-09-28T07:17:20.573Z",
"pubdate": "2026-09-28T07:17:20.573Z",
"executiveSummary": "A critical OS command injection vulnerability exists within the Unzip Handler component of aaPanel (BaoTa) versions up to 11.8.0. The vulnerability resides in the panelTask.bt_task._unzip function located in /www/server/panel/class/panelTask.py.\nThe flaw arises from improper validation of the 'Password' argument, which allows an attacker to inject arbitrary system commands into the execution flow. This vulnerability is remotely exploitable, requiring no prior authentication, and provides attackers with the ability to execute unauthorized commands with the privileges of the web server process.\nGiven that the exploit is publicly disclosed and the vendor has not provided a response or patch, the risk is classified as critical. Successful exploitation leads to full system compromise, allowing for data exfiltration, service disruption, or further lateral movement within the network infrastructure.\nAttackers can leverage this vulnerability to gain remote code execution (RCE) without legitimate credentials, making it a high-priority target for automated exploitation tools and threat actors.",
"technicalDetails": "The vulnerability is localized within the /www/server/panel/class/panelTask.py file, specifically inside the 'panelTask.bt_task._unzip' function. This function is responsible for handling archive decompression tasks initiated through the aaPanel interface.\nThe root cause is a failure to properly sanitize or parameterize the 'Password' input variable before it is passed to a backend system shell or command-line utility used for the unzip operation. In standard implementations, archive utilities (such as 'unzip' or '7z') often utilize command-line flags to handle protected archives; if the input is improperly concatenated into a command string, it permits shell metacharacter injection.\nAn attacker can exploit this by crafting a malicious payload containing shell control characters (e.g., ;, &&, ||, or backticks). When the '_unzip' function processes the 'Password' argument, these characters allow the termination of the intended archive utility command and the initiation of arbitrary, attacker-supplied OS commands.\nThe attack flow follows these steps: 1) The attacker identifies a target instance of aaPanel. 2) The attacker crafts a request, such as an HTTP POST, targeting the endpoint responsible for invoking the unzip task. 3) The attacker injects the payload into the 'Password' parameter. 4) The application, failing to validate the input, passes the malicious string directly to the operating system's execution environment. 5) The system executes the injected command with the privileges of the user running the aaPanel service (typically 'root' or 'www').\nBecause the execution occurs at the OS level, the impact is severe. An attacker can achieve complete control over the host, enabling the deployment of persistence mechanisms, rootkits, or ransomware. Post-exploitation, the attacker can access sensitive configuration files, database credentials, and any data managed by the panel, effectively bypassing all application-level access controls.\nThe vulnerability is accessible remotely via the network, and the lack of authentication requirements in the specific execution path significantly lowers the bar for exploitation, allowing unauthorized actors to compromise the system from any point on the network."
}