A vulnerability was determined in aaPanel BaoTa up to 11.8.0. The affected element is the function panelTask.bt_task._unzip of the file /www/server/panel/class/panelTask.py of the component Unzip Handler. Executing a manipulation of the argument Password can lead to os command injection. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized. The vendor was co [truncated]
CVE-2026-101008 is a high-severity vulnerability in the aaPanel BaoTa file merge handler. The vulnerability allows for remote command injection via manipulation of the split_file_path argument in the merge_split_file function of /www/server/panel/class/files.py. The exploit has been made public, and although the vendor was contacted, no response was received. Defenders should assess exposure, prioritize r [truncated]
A vulnerability was found in aaPanel BaoTa up to 11.8.0 in the Database Backup Handler component. The issue is caused by os command injection in the InputSql function of the class/database.py file, which can be triggered remotely by manipulating the Password argument. The exploit has been publicly disclosed, and although the vendor was notified, no response was received.