CVE-2026-101011 | aaPanel BaoTa up to 11.8.0 Domain domainMod.py get_domain_status get sql injection

SecurityVulns

A vulnerability categorized as problematic has been discovered in aaPanel BaoTa up to 11.8.0. This affects the function get_domain_status of the file /www/server/panel/mod/project/domain/domainMod.py of the component Domain Handler. The manipulation of the argument get results in sql injection.

This vulnerability is known as CVE-2026-101011. It is possible to launch the attack remotely. Furthermore, an exploit is available.

The vendor was contacted early about this disclosure but did not respond in any way.VulDB Recent EntriesRead More