Act nowDisclosed

Advisory · CVE-2026-101008

aaPanel/BaoTa file-merge command injection yields root RCE

The merge_split_file endpoint in aaPanel BaoTa builds a shell command around the attacker-supplied split_file_path argument, so an authenticated panel user can execute arbitrary commands as root. A working public exploit exists and no vendor fix has been published.

Vendor
aaPanel
Product
BaoTa
Identifier / CWE
CVE-2026-101008
CWE-74, CWE-77
Action timing
Immediate
ELI5

Explain it like I’m five

The hosting panel merges split files by pasting a filename straight into a shell command. An attacker names the 'file' something like ';id > /tmp/pwned;echo ' and the panel happily runs the attacker's command as root.

SIMPLIFIED_ATTACK_PATH04 STEPS
  1. 01Authenticated upload

    The attacker, logged in to the panel, uploads a small JSON file whose split_file_path value carries shell metacharacters.

  2. 02Merge request

    The attacker posts /files?action=merge_split_file pointing at that JSON file.

  3. 03Shell command assembled

    merge_split_file in class/files.py interpolates the path into a shell command and runs it with shell=True.

  4. 04Root execution

    The panel process runs as root, so the injected command executes with full host privileges; the API returns success either way.

What happened

CVE-2026-101008 is an OS command injection in the merge_split_file function of /www/server/panel/class/files.py in aaPanel BaoTa. According to the CVE record, the split_file_path argument is not sanitized before being interpolated into a shell command executed with shell=True; the public exploit demonstrates the injected command running as root while the panel’s API returns a normal success response. The record lists BaoTa 11.0 through 11.8.0 as affected and rates it critical at CVSS 9.1 (requires an authenticated panel session). The discloser states the vendor was contacted early and did not respond, and no patched release has been announced.

aaPanel runs its panel process as root and manages the whole server, so this is not a limited privilege gain: any authenticated panel user with access to the file tools can take over the host.

What to do

  1. Remove the panel from the public internet: bind it to localhost, restrict access to a management network or VPN, and firewall the panel port.
  2. Treat the file-merge function as unsafe until the vendor ships a fix; do not rely on it in untrusted multi-tenant setups.
  3. Review panel access logs for merge_split_file calls and unexpected file uploads under /tmp around the disclosure date.
  4. Audit who holds panel administrator credentials and rotate them if unauthorized activity cannot be excluded.
  5. Watch the aaPanel/BaoTa repository for a security release before re-enabling broader access.

Management note

A hosting control panel is the highest-leverage target on a server: it already holds root and the keys to everything. A publicly demonstrated, unauthenticated-to-root-adjacent flaw with no vendor patch is a containment problem first and a patching problem second. Narrow who can reach the panel today; worry about the feature later.