Command Injection in aaPanel BaoTa via File Merge Handler
An unauthenticated remote command injection vulnerability in the aaPanel BaoTa File Merge Handler allows attackers to execute arbitrary system commands via the split_file_path parameter.
CVE search metadata
CVE search record: CVE-2026-101008. Severity: critical. CVSS: 9.1. KEV: no. Product: BaoTa (<= 11.8.0). Brief: Command Injection in aaPanel BaoTa via File Merge Handler. Brief link: https://feed.craftedsignal.io/briefs/2026-09-aapanel-command-injection/
What's new
aaPanel BaoTa versions up to 11.8.0 contain a critical command injection vulnerability in the merge_split_file function, located within the file /www/server/panel/class/files.py. The vulnerability exists within the File Merge Handler component. An unauthenticated remote attacker can exploit this by sending a specially crafted request containing a malicious split_file_path argument. Because the application fails to properly sanitize this input before passing it to the underlying system shell, it allows for the execution of arbitrary commands with the privileges of the web application user. This flaw is publicly disclosed and currently lacks a vendor-provided patch. Defenders should treat this as a high-priority exposure, as public exploit code increases the likelihood of active exploitation.
Impact
Successful exploitation results in full remote code execution on the target server. Given that aaPanel is a web hosting control panel, successful compromise typically yields administrative control over the underlying Linux OS and all hosted web content. This allows for data exfiltration, service disruption, and the potential use of the server as a pivot point within the infrastructure.
Recommendation
- Restrict external network access to the aaPanel management interface immediately, ensuring it is not reachable from the public internet.
- Implement WAF rules to inspect HTTP requests for shell metacharacters (e.g., ;, |, &&, `) within the split_file_path parameter targeting the /www/server/panel/class/files.py file path.
- Monitor system audit logs for unexpected processes spawned by the web server user (typically www or www-data).
- Audit the server for evidence of post-exploitation activity, such as the creation of unauthorized web shells or persistence mechanisms.
Immediate actions
Block external access to the aaPanel administrative interface.
Mitigations
Implement WAF filter for shell metacharacters in split_file_path.
CVE-2026-101008
Detection coverage 1
Detect CVE-2026-101007 Exploitation - Remote Command Injection in BaoTa
highDetects exploitation of CVE-2026-101007 by identifying shell metacharacters within the Password argument of database backup requests.
Detection queries are available on the platform. Get full rules →