CVE-2026-101007 | aaPanel BaoTa up to 11.8.0 Database Backup class/database.py InputSql Password os command injection

SecurityVulns

A vulnerability was found in aaPanel BaoTa up to 11.8.0 and classified as critical. This issue affects the function InputSql of the file class/database.py of the component Database Backup Handler. Such manipulation of the argument Password leads to os command injection.

This vulnerability is documented as CVE-2026-101007. The attack can be executed remotely. Additionally, an exploit exists.

The vendor was contacted early about this disclosure but did not respond in any way.VulDB Recent EntriesRead More