aaPanel BaoTa Unzip panelTask.py panelTask.bt_task._unzip os command injection
Published Sep 28, 2026
9.3
CRITICALCVSS 4.0
EPSS 1.76%
Description
A vulnerability was determined in aaPanel BaoTa up to 11.8.0. The affected element is the function panelTask.bt_task._unzip of the file /www/server/panel/class/panelTask.py of the component Unzip Handler. Executing a manipulation of the argument Password can lead to os command injection. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.
Affected products
-
- Version 11.0StatusaffectedConstraints-
- Version 11.1StatusaffectedConstraints-
- Version 11.2StatusaffectedConstraints-
- Version 11.3StatusaffectedConstraints-
- Version 11.4StatusaffectedConstraints-
- Version 11.5StatusaffectedConstraints-
- Version 11.6StatusaffectedConstraints-
- Version 11.7StatusaffectedConstraints-
- Version 11.8.0StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
No data.
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (6)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-88106 Advisory
- https://gist.github.com/zuesdevil/ba0b8aa9f7516ea0e57b173146ce5408 exploit
- https://vuldb.com/cve/CVE-2026-101009 third-party-advisory
- https://vuldb.com/submit/922625 third-party-advisory
- https://vuldb.com/vuln/410879 vdb-entrytechnical-description
- https://vuldb.com/vuln/410879/cti signaturepermissions-required
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-88106 | Advisory | |
| https://gist.github.com/zuesdevil/ba0b8aa9f7516ea0e57b173146ce5408 | exploit | |
| https://vuldb.com/cve/CVE-2026-101009 | third-party-advisory | |
| https://vuldb.com/submit/922625 | third-party-advisory | |
| https://vuldb.com/vuln/410879 | vdb-entrytechnical-description | |
| https://vuldb.com/vuln/410879/cti | signaturepermissions-required |
Change history (0)
No recorded changes yet.