CVE-2026-101008 | aaPanel BaoTa up to 11.8.0 File Merge files.py merge_split_file split_file_path command injection

SecurityVulns

A vulnerability was found in aaPanel BaoTa up to 11.8.0. It has been classified as very critical. Impacted is the function merge_split_file of the file /www/server/panel/class/files.py of the component File Merge Handler. Performing a manipulation of the argument split_file_path results in command injection.

This vulnerability is reported as CVE-2026-101008. The attack is possible to be carried out remotely. Moreover, an exploit is present.

The vendor was contacted early about this disclosure but did not respond in any way.VulDB Recent EntriesRead More