Description
A vulnerability has been found in aaPanel BaoTa up to 11.8.0. This issue affects the function InputSql of the file class/database.py of the component Database Backup Handler. Such manipulation of the argument Password leads to os command injection. The attack can be executed remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Published: 2026-09-28
Score: 9.3 Critical
EPSS: n/a
KEV: No
Impact: Remote Command Execution
Action: Patch Now
AI Analysis

Impact

The vulnerability resides in the InputSql function of aaPanel BaoTa's database backup handler. An attacker can manipulate the Password argument to inject arbitrary shell commands, resulting in remote command execution with the privileges of the web server process. This flaw is a classic OS command injection (CWE-77, CWE-78). Because the functionality can be triggered remotely via a crafted HTTP request, an attacker could compromise the host without needing local access.

Affected Systems

Affected vendors: aaPanel for its BaoTa control panel. Any installation at or before version 11.8.0 of aaPanel BaoTa is vulnerable. The database backup feature (class/database.py) processes the Password parameter unsafely. All customers running the affected releases and relying on the backup module are at risk.

Risk and Exploitability

CVSS score 9.3 signifies critical severity, indicating high impact and ease of exploitation. EPSS is not available, but the public disclosure and vendor unresponsiveness suggest the risk is real and likely. The vulnerability can be exercised by sending a crafted request to the backup endpoint; the stack trace shows the direct use of the Password argument in an os.exec call. The flaw is not limited to local users, so the attack vector is remote and traffic can be intercepted from the network. Because the flaw runs in the web process, successful exploitation results in persistent compromise of the host.

Generated by OpenCVE AI on September 28, 2026 at 07:20 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade aaPanel BaoTa to the latest release that fixes the OS command injection in the database backup handler; for example, install the patch that removes unsanitized usage of the Password parameter.
  • If an upgrade cannot be performed immediately, disable the Database Backup feature or restrict access to the panel by firewall or access control to limit exposure to trusted administrators.
  • Ensure any remaining usage of the Password field is sanitized or validated against a whitelist, and avoid passing it directly to shell commands; use safe APIs or parameter binding when interacting with the operating system.

Generated by OpenCVE AI on September 28, 2026 at 07:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 28 Sep 2026 06:45:00 +0000

Type Values Removed Values Added
Description A vulnerability has been found in aaPanel BaoTa up to 11.8.0. This issue affects the function InputSql of the file class/database.py of the component Database Backup Handler. Such manipulation of the argument Password leads to os command injection. The attack can be executed remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Title aaPanel BaoTa Database Backup database.py InputSql os command injection
First Time appeared Aapanel
Aapanel baota
Weaknesses CWE-77
CWE-78
CPEs cpe:2.3:a:aapanel:baota:*:*:*:*:*:*:*:*
Vendors & Products Aapanel
Aapanel baota
References
Metrics cvssV2_0

{'score': 8.3, 'vector': 'AV:N/AC:L/Au:M/C:C/I:C/A:C/E:POC/RL:ND/RC:C'}

cvssV3_0

{'score': 8.4, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H/E:P/RL:X/RC:C'}

cvssV3_1

{'score': 8.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H/E:P/RL:X/RC:C'}

cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-28T06:30:09.664Z

Reserved: 2026-09-27T11:05:04.562Z

Link: CVE-2026-101007

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-28T07:17:20.197

Modified: 2026-09-28T07:17:20.197

Link: CVE-2026-101007

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-28T07:30:17Z

Weaknesses
  • CWE-77

    Improper Neutralization of Special Elements used in a Command ('Command Injection')

  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')