Unknown · Aapanel Baota · CVE-2026-101007
**Name of the Vulnerable Software and Affected Versions**
aaPanel BaoTa versions prior to 11.8.1
**Description**
An OS command injection flaw exists in the Database Backup Handler component. The issue occurs within the `InputSql()` function located in the `class/database.py` file. A remote attacker can exploit this by manipulating the `Password` variable, allowing for the execution of arbitrary operating system commands.
**Recommendations**
Update aaPanel BaoTa to a version later than 11.8.0.
As a temporary mitigation, restrict access to the Database Backup Handler component.