天下漏洞,尽知其名
HIGH

CVE-2026-101007 aaPanel BaoTa 操作系统命令注入漏洞

影响攻击者可远程执行任意操作系统命令

AI 研判

aaPanel BaoTa 11.8.0 及之前版本的数据库备份处理组件存在命令注入漏洞。该漏洞位于 class/database.py 文件的 InputSql 函数中,攻击者可通过操纵 Password 参数注入操作系统命令。漏洞利用细节已公开,且厂商未对此披露作出回应。

影响范围

aaPanel BaoTa

aaPanel BaoTa 11.8.0 及更早版本(依据描述中的 up to 11.8.0)。

漏洞详情

该漏洞属于操作系统命令注入(OS Command Injection)。在数据库备份处理流程中,InputSql 函数未对传入的 Password 参数进行充分过滤或转义,导致攻击者可将恶意命令拼接进系统调用中执行。攻击者可远程发起利用,且公开的 PoC 可能已被实际使用。

利用条件与风险

利用需能访问受影响的数据库备份相关接口或功能,具体前置条件暂无公开信息;由于利用代码已公开且可远程触发,实战风险较高。

修复建议

官方暂未发布修复版本或回应,建议关注 aaPanel 官方公告;临时缓解措施包括限制相关接口的访问权限、对 Password 等参数进行严格过滤,或暂时禁用数据库备份功能。

原始情报

A vulnerability has been found in aaPanel BaoTa up to 11.8.0. This issue affects the function InputSql of the file class/database.py of the component Database Backup Handler. Such manipulation of the argument Password leads to os command injection. The attack can be executed remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.