CVE-2022-48079: Mengnai Aapanel Host System

Critical severity, CVSS 9.8. EPSS: 1.4% chance of exploitation in the next 30 days.

Monnai aaPanel host system v1.5 contains an access control issue which allows attackers to escalate privileges and execute arbitrary code via uploading a crafted PHP file to the virtual host directory of the system.

Affected products

  • Mengnai Aapanel Host System: version 1.5 only

Published 2023-02-02. Last modified 2026-06-17.