CVE-2026-29859 - Vulnerability Analysis
CriticalCVSS: 9.8Last Updated: March 19, 2026
aaPanel - Unrestricted File Upload
Overview
aaPanel v7.57.0 contains an unrestricted file upload vulnerability caused by improper validation of uploaded files, letting attackers execute arbitrary code by uploading crafted files, exploit requires no special privileges.
Severity & Score
Impact
Attackers can execute arbitrary code remotely by uploading malicious files, potentially leading to full system compromise.
Mitigation
Update to the latest version of aaPanel.
References
Social Media Activity(1 post)
š“ CVE-2026-29859 - Critical (9.8) An arbitrary file upload vulnerability in aaPanel v7.57.0 allows attackers to execute arbitrary code via uploading a crafted file. š https://www.thehackerwire.com/vulnerability/CVE-2026-29859/ #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
View original postRelated Resources
Details
- CVE ID
- CVE-2026-29859
- Severity
- Critical
- CVSS Score
- 9.8
- Type
- unrestricted_file_upload
- Status
- confirmed
- EPSS
- 7.2%
- Social Posts
- 1
CWE
- CWE-94
CVSS Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H