CVE-2026-101007: aaPanel BaoTa Database Backup database.py InputSql os command injection
A vulnerability has been found in aaPanel BaoTa up to 11.8.0. This issue affects the function InputSql of the file class/database.py of the component Database Backup Handler. Such manipulation of the argument Password leads to os command injection. The attack can be executed remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What access does an attacker need to exploit this issue?
The published vector indicates network-reachable exploitation with low attack complexity, but it also requires high privileges and user interaction. Exploitation targets the Password argument handled by the Database Backup Handler's InputSql function.
Which deployments should be considered affected?
aaPanel BaoTa versions up to and including 11.8.0 are identified as affected. The available information does not state whether a particular default configuration exposes the vulnerable Database Backup Handler.
Is public exploit information available?
Yes. The exploit has been publicly disclosed and may be used, increasing the likelihood that authenticated high-privilege users could attempt exploitation.
Is a vendor fix or mitigation available?
The provided information does not identify a patch or workaround. It states that the vendor was contacted early about the disclosure but did not respond.