CVE-2026-101008: aaPanel BaoTa File Merge files.py merge_split_file command injection
A vulnerability was found in aaPanel BaoTa up to 11.8.0. Impacted is the function mergesplitfile of the file /www/server/panel/class/files.py of the component File Merge Handler. Performing a manipulation of the argument splitfilepath results in command injection. The attack is possible to be carried out remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What level of access does an attacker need to exploit this issue?
The published CVSS vector indicates that the attacker needs high privileges (PR:H). Exploitation does not require user interaction and can be performed remotely.
Which deployments are known to be affected?
aaPanel BaoTa versions up to and including 11.8.0 are identified as affected. The issue is in the File Merge Handler's merge_split_file function in /www/server/panel/class/files.py.
Is exploit code available?
Yes. The vulnerability information states that a public exploit exists, increasing the likelihood that attackers with the required privileges could attempt exploitation.
Is a vendor fix or response known to be available?
No vendor response is reported in the provided information. The vendor was contacted before disclosure but did not respond.