Skip to content
Threat Feed
critical threat exploited

Command Injection in aaPanel BaoTa via File Merge Handler

An unauthenticated remote command injection vulnerability in the aaPanel BaoTa File Merge Handler allows attackers to execute arbitrary system commands via the split_file_path parameter.

CVE search metadata

CVE search record: CVE-2026-101008. Severity: critical. CVSS: 9.1. KEV: no. Product: BaoTa (<= 11.8.0). Brief: Command Injection in aaPanel BaoTa via File Merge Handler. Brief link: https://feed.craftedsignal.io/briefs/2026-09-aapanel-command-injection/

What's new

  • 1. added coverage for BaoTa (<= 11.8.0) Sep 28, 08:49 via nvd
  • 2. added detection rule: Detect CVE-2026-101007 Exploitation - Remote Command Injection in BaoTa Sep 28, 08:49 via nvd

aaPanel BaoTa versions up to 11.8.0 contain a critical command injection vulnerability in the merge_split_file function, located within the file /www/server/panel/class/files.py. The vulnerability exists within the File Merge Handler component. An unauthenticated remote attacker can exploit this by sending a specially crafted request containing a malicious split_file_path argument. Because the application fails to properly sanitize this input before passing it to the underlying system shell, it allows for the execution of arbitrary commands with the privileges of the web application user. This flaw is publicly disclosed and currently lacks a vendor-provided patch. Defenders should treat this as a high-priority exposure, as public exploit code increases the likelihood of active exploitation.

Impact

Successful exploitation results in full remote code execution on the target server. Given that aaPanel is a web hosting control panel, successful compromise typically yields administrative control over the underlying Linux OS and all hosted web content. This allows for data exfiltration, service disruption, and the potential use of the server as a pivot point within the infrastructure.

Recommendation

  1. Restrict external network access to the aaPanel management interface immediately, ensuring it is not reachable from the public internet.
  2. Implement WAF rules to inspect HTTP requests for shell metacharacters (e.g., ;, |, &&, `) within the split_file_path parameter targeting the /www/server/panel/class/files.py file path.
  3. Monitor system audit logs for unexpected processes spawned by the web server user (typically www or www-data).
  4. Audit the server for evidence of post-exploitation activity, such as the creation of unauthorized web shells or persistence mechanisms.

Immediate actions

Block external access to the aaPanel administrative interface.

IT Operations 24h

Mitigations

Implement WAF filter for shell metacharacters in split_file_path.

immediate SOC

CVE-2026-101008

Detection coverage 1

Detect CVE-2026-101007 Exploitation - Remote Command Injection in BaoTa

high

Detects exploitation of CVE-2026-101007 by identifying shell metacharacters within the Password argument of database backup requests.

sigma tactics: initial_access techniques: T1190 sources: webserver

Detection queries are available on the platform. Get full rules →