Skip to content
CVE Alert: CVE-2026-101009 – aaPanel

CVE Alert: CVE-2026-101009 – aaPanel

Redpacketsecurity •admin • September 28, 2026

A vulnerability was determined in aaPanel BaoTa up to 11.8.0. The affected element is the function panelTask.bt_task._unzip of the file /www/server/panel/class/panelTask.py of the component Unzip Handler. Executing a manipulation of the argument Password can lead to os command injection. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early this disclosure but did not respond in any way.

**Risk verdict:** High risk for exposed management panels: public exploit disclosure warrants urgent review, although no KEV or active-exploitation status is provided.

**Why this matters:** Successful command execution could let an attacker compromise the panel host, disrupt hosted services, or access customer data and credentials. On shared or hosting infrastructure, compromise may also provide a foothold to attack other sites or systems managed from the same server.

**Most likely attack path:** The service is network-reachable and exploitation appears low complexity, but it requires high privileges and user interaction. A likely path is an authenticated, sufficiently privileged account arranging for a panel user or administrator to process a crafted archive or password value; the changed scope suggests consequences may extend beyond the panel component. The exact required role and user action are not established by the supplied data.

**Who is most exposed:** Internet-accessible, self-hosted web-hosting control panels are the primary concern, particularly on shared-hosting or VPS systems where one panel manages multiple sites.

Alert on panel processes spawning shells or unexpected command-line utilities.

Review unzip-task logs for unusual password values or command metacharacters.

Look for new web files, scheduled tasks, users, or outbound connections after unzip activity.

Mitigation and prioritisation:

Confirm the vendor’s fixed release; the supplied data does not identify one. Patch promptly after testing.

Restrict panel access to trusted networks and disable or limit the affected unzip workflow where feasible.

Review privileged panel accounts and investigate hosts that processed suspicious archives.

Back up panel configuration and hosted data before changes; verify service integrity afterwards.

A considerable amount of time and effort goes into maintaining this website, creating backend automation and creating new features and content for you to make actionable intelligence decisions. Everyone that supports the site helps enable new functionality.

If you like the site, please support us on Patreon or Buy Me A Coffee using the buttons below.

Extracted Entities