CVE-2026-101010: aaPanel BaoTa data.py getData sql injection
Published Sep 28, 2026
·Updated
A vulnerability was identified in aaPanel BaoTa up to 11.8.0. The impacted element is the function getData of the file /www/server/panel/class/data.py. The manipulation of the argument logtype leads to sql injection. It is possible to initiate the attack remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
1 affected component
aaPanel BaoTa<=11.8.0
Event History
Sep 28, 2026
CVE Published
via MITRE·07:15 AM
Data Sourced
via MITRE·07:15 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:16 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Which aaPanel BaoTa versions should be considered affected?
aaPanel BaoTa versions up to and including 11.8.0 are identified as affected.
2
Does an attacker need access to the target before exploiting this issue?
The attack can be initiated remotely, but the supplied CVSS vector indicates that high privileges are required.
3
Is exploit code available?
Yes. The vulnerability information states that a public exploit is available and may be used.