Skip to content
aapanel-cve

aapanel-cve

Sploitus • September 23, 2026

Vulnerabilities identified in **aaPanel v8.22.0** (GitHub commit `4af59b2386e118fc0e4b2ae838dacac992d16b1c`, released 2026-08-27).

**Status:** Vendor notified ([email protected]) on **2026-09-23**. CVE identifiers pending assignment. Coordinated disclosure in progress.

> Each finding lives in its own folder with a README, a proof-of-concept and a validation harness. The concrete folder URL is intended to be attached to the corresponding CVE record.

| 1 | [`aapanel-rce/`](aapanel-rce/) | OS command injection (RCE) — Zip / UnZip / SetFileAccess | Panel user | Critical |

| 2 | [`aapanel-xrealip/`](aapanel-xrealip/) | Unauthenticated IP allowlist + brute-force bypass via `X-Real-Ip` header | None | High |

| 3 | [`aapanel-lfi/`](aapanel-lfi/) | Local file disclosure — `/download` + `/v2/download` (patch-gap of CVE-2026-29858) | Panel session / tmp_token | High |

| `aapanel-rce/validate_rce.py` | Executes the exact shell strings aaPanel constructs in a POSIX shell; confirms command execution via a marker file. |

| `aapanel-xrealip/validate_xrealip.py` | Minimal Flask harness replicating `BTPanel/__init__.py:640-646` + `GetClientIp()`/`check_ip_panel()`/`limit_address()`; 3/3 scenarios pass. |

| `aapanel-lfi/validate_lfi.py` | Re-implements `/download` (v1) and `/v2/download` (v2) handlers verbatim; 6/6 checks pass. |

- `2026-09-23` — vendor notified (email to [email protected]).

- `2026-09-23` — CVE request(s) submitted to VulDB (CNA) after vendor .

- `pending` — vendor fix / CVE assignment / this repository goes public (intended within the 90-day coordinated window unless arranged otherwise).

Provided for coordinated disclosure and security research educational purposes only. Findings were validated against the official public source snapshot and execution harnesses on the researcher's own test host. No production systems were targeted. Do not use against systems you do not own.

Extracted Entities