CVE-2026-44403: Wing FTP Server < 8.1.3 Authenticated Remote Code Execution via Session Serialization
Wing FTP Server before 8.1.3 contains an authenticated remote code execution vulnerability in the session serialization mechanism that allows authenticated administrators to inject arbitrary Lua code through the domain admin mydirectory field. Attackers can exploit unsafe serialization of session values into Lua source code without proper escaping of closing delimiters, causing the injected code to be executed when the poisoned session is loaded via loadfile().
Security readout for executives and security teams
Plain-English summary
This flaw lets an authenticated Wing FTP administrator turn a saved session value into code execution on the server. It is not a drive-by internet bug: the attacker needs admin access first. If admin credentials are compromised, the FTP server can become a full execution foothold.
Executive priority
Prioritize remediation for internet-facing or business-critical Wing FTP servers. The required admin privilege lowers mass-exploitation likelihood, but successful abuse can provide direct server code execution after credential compromise.
Technical view
Wing FTP Server before 8.1.3 is reported to serialize session values into Lua source without safely escaping closing delimiters. A domain admin mydirectory value can poison the session, and later loading through loadfile() executes injected Lua code. The CVE maps to CWE-94 and has CVSS 4.0 score 8.6.
Likely exposure
Organizations running Wing FTP Server, especially versions identified as before 8.1.3, should review exposure. The source bundle’s affected-version data is inconsistent with the title, so confirm exact installed and fixed versions against Wing FTP release notes.
Exploitation context
The source bundle reports authenticated administrator privileges are required, with network access, low complexity, and no user interaction. It does not show CISA KEV listing or cite confirmed active exploitation. Treat this as serious post-authentication RCE, especially where admin accounts are shared or externally reachable.
Researcher notes
Evidence supports a session-serialization code injection path involving Lua source generation and loadfile(). The available bundle does not include exploit telemetry, KEV status, or complete fixed-version clarity beyond the <8.1.3 title and vendor release-note reference.
Mitigation direction
Check Wing FTP Server release notes for the fixed version and upgrade promptly.
Restrict administrative access to trusted networks and identities only.
Review domain administrator accounts and remove unnecessary privileges.
Rotate admin credentials if compromise is suspected.
Monitor vendor and CVE records for updated remediation guidance.
Validation and detection
Inventory Wing FTP Server instances and record exact versions.
Confirm whether any instance is before the vendor-fixed release.
Review admin access logs for unusual domain setting changes.
Audit domain admin mydirectory values for unexpected content.
Verify administrative interfaces are not broadly internet-exposed.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Potential ATT&CK relevance
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
cwe · medium confidence lookup
CWE-94: Code execution behavior lookup
Code execution and unsafe deserialization weaknesses often justify reviewing execution behavior and process telemetry. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.
The CVE wording references code or command execution, so execution technique review may help defensive triage. This is a Glexia inferred lookup path, not an official MITRE, ATT&CK, or CVE Program mapping.
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
2CVSS vectors
3Timeline events
1ADP providers
3Source links
SSVC decision data
CISA-ADPCISA Coordinator
Timestamp
Version
2.0.3
Exploitation: noneAutomatable: noTechnical Impact: total
CVSS vector scores
2 official scores
We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.
CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.
CWE-94 · source CWE mapping
Improper Control of Generation of Code ('Code Injection')
Improper Control of Generation of Code ('Code Injection') represents a recurring weakness pattern that can create exploitable paths when design, validation, or implementation controls are missing.