Advisory · CVE-2026-101007
aaPanel/BaoTa database-backup command injection runs attacker commands as root
The InputSql function in class/database.py of aaPanel BaoTa passes the attacker-supplied Password parameter into a shell command, so an authenticated panel user can execute arbitrary commands as root. A working public exploit exists and no vendor fix has been published.
- Vendor
- aaPanel
- Product
- BaoTa
- Identifier / CWE
- CVE-2026-101007
CWE-77, CWE-78 - Action timing
- Immediate
Explain it like I’m five
The panel's database-backup tool pastes the backup password into a shell command. An attacker types a 'password' that is actually a shell command, and the panel runs it as root.
- 01Database backup request
The attacker, logged in to the panel, calls the database backup handler with a crafted Password argument.
- 02InputSql
InputSql in class/database.py interpolates the Password value into a shell command without sanitization.
- 03Shell execution
The command runs with shell=True, so embedded metacharacters execute as separate commands.
- 04Root compromise
Because the panel process runs as root, the injected command executes with full host privileges.
What happened
CVE-2026-101007 is an OS command injection in the InputSql function of class/database.py in aaPanel BaoTa. According to the CVE record, the Password argument of the database backup handler is passed into a shell command without sanitization, letting a remote attacker with an authenticated panel session execute arbitrary commands. The record lists BaoTa 11.0 through 11.8.0 as affected and rates it high at CVSS 8.4. The exploit is publicly disclosed; the discloser states the vendor was contacted early and did not respond, and no patched release has been announced.
This is the second of three authenticated root-level command injections disclosed against the same BaoTa release line, alongside CVE-2026-101008 and CVE-2026-101009.
What to do
- Remove the panel from the public internet: bind it to localhost, restrict access to a management network or VPN, and firewall the panel port.
- Treat the database backup handler as unsafe until the vendor ships a fix; avoid triggering backups through the panel in hostile or shared environments.
- Review panel access logs for database backup operations with unusual or shell-like Password parameters.
- Audit who holds panel administrator credentials and rotate them if unauthorized activity cannot be excluded.
- Watch the aaPanel/BaoTa repository for a security release before re-enabling broader access.
Management note
One command injection is a bug; three in the same release is a pattern. This BaoTa line is currently carrying multiple publicly exploited paths from a logged-in panel user straight to root. Until the vendor responds, the only honest posture is a panel you can reach only from the management network, and a list of every account that can log in to it.