Skip to content
Critical Vulnerability Disclosed in aaPanel Allowing Remote Command Injection

Critical Vulnerability Disclosed in aaPanel Allowing Remote Command Injection

First seen 28 Sep 2026, 17:08 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •September 28, 2026 at 18:20 UTC
  • •CVE-2026-101009 allows remote OS command injection in aaPanel versions up to 11.8.0.
  • •The vulnerability was disclosed publicly, increasing the urgency for affected systems to be reviewed.
  • •No response from the vendor has been reported, raising concerns about timely mitigation.

A high-risk vulnerability, CVE-2026-101009, was identified in aaPanel up to version 11.8.0, affecting the unzip functionality that could lead to OS command injection. The flaw allows remote attackers to manipulate the password argument, potentially compromising the host system and disrupting services. The vendor was contacted but did not respond to the disclosure. The vulnerability has been publicly disclosed, and while there is no indication of active exploitation, the risk remains significant for exposed management panels, especially on shared hosting environments. Security professionals are urged to review logs for unusual activity and restrict access to the affected panels. The vulnerability was officially published on September 28, 2026.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-03-18
CVE-2026-29858 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-23
Vendor notified of vulnerabilities
The vendor was informed of multiple vulnerabilities in aaPanel, including CVE-2026-101009, but did not respond.
Sploitus
2026-09-28
CVE-2026-101009 published
CVE-2026-101009 was officially published, detailing the remote command injection vulnerability in aaPanel.
Redpacketsecurity

More articles in this cluster (4)

Following this threat?

Track CVE-2026-101009 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed