Advisory · CVE-2026-101009
aaPanel/BaoTa unzip handler command injection runs attacker commands as root
The panelTask.bt_task._unzip function in aaPanel BaoTa interpolates the attacker-supplied Password argument into a shell command, so an authenticated panel user can execute arbitrary commands as root. A working public exploit exists and no vendor fix has been published.
- Vendor
- aaPanel
- Product
- BaoTa
- Identifier / CWE
- CVE-2026-101009
CWE-77, CWE-78 - Action timing
- Immediate
Explain it like I’m five
The panel's unzip tool stuffs the archive password into a shell command. An attacker hands it a 'password' that is really a shell command, and the panel runs it as root.
- 01Unzip request
The attacker, logged in to the panel, triggers the unzip handler with a crafted Password argument.
- 02_unzip
panelTask.bt_task._unzip in class/panelTask.py interpolates the Password value into a shell command without sanitization.
- 03Shell execution
The command runs through a shell, so embedded metacharacters execute as separate commands.
- 04Root compromise
Because the panel process runs as root, the injected command executes with full host privileges.
What happened
CVE-2026-101009 is an OS command injection in the panelTask.bt_task._unzip function of /www/server/panel/class/panelTask.py in aaPanel BaoTa. According to the CVE record, the Password argument of the unzip handler is passed into a shell command without sanitization, letting a remote attacker with an authenticated panel session execute arbitrary commands. The record lists BaoTa 11.0 through 11.8.0 as affected and rates it high at CVSS 8.4. The exploit is publicly disclosed; the discloser states the vendor was contacted early and did not respond, and no patched release has been announced.
This is the third of three authenticated root-level command injections disclosed against the same BaoTa release line, alongside CVE-2026-101007 and CVE-2026-101008.
What to do
- Remove the panel from the public internet: bind it to localhost, restrict access to a management network or VPN, and firewall the panel port.
- Treat the unzip handler as unsafe until the vendor ships a fix; avoid processing untrusted archives through the panel.
- Review panel access logs for unzip operations with unusual or shell-like Password parameters.
- Audit who holds panel administrator credentials and rotate them if unauthorized activity cannot be excluded.
- Watch the aaPanel/BaoTa repository for a security release before re-enabling broader access.
Management note
One command injection is a bug; three in the same release is a pattern. This BaoTa line is currently carrying multiple publicly exploited paths from a logged-in panel user straight to root. Until the vendor responds, the only honest posture is a panel you can reach only from the management network, and a list of every account that can log in to it.