CVE-2026-29858 describes a Local File Inclusion (LFI) vulnerability in aaPanel v7.57.0, stemming from insufficient path validation, which can lead to sensitive information exposure. Rated 7.5 HIGH on the CVSS scale, this vulnerability allows an unauthenticated attacker to exploit it remotely over the network with low attack complexity, resulting in high confidentiality impact. Currently, there is no evidence of active exploitation, nor are there public exploits available on platforms like Metasploit or ExploitDB. Community discussion and media coverage regarding this CVE are also minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
7.57.0CPE matchmatch criteria | cpe:2.3:a:aapanel:aapanel:7.57.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.