CVE-2026-101010 | aaPanel BaoTa up to 11.8.0 data.py getData log_type sql injection
A vulnerability was found in aaPanel BaoTa up to 11.8.0. It has been rated as problematic. The impacted element is the function getData of the file /www/server/panel/class/data.py. The manipulation of the argument log_type leads to sql injection.
This vulnerability is traded as CVE-2026-101010. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
The vendor was contacted early about this disclosure but did not respond in any way.VulDB Recent EntriesRead More