CVE 7.2 HIGH

Wing FTP Server 8.1.2 Authenticated Remote Code Execution via Session Serialization_CVE-2026-44403

7.2 / 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Description

Wing FTP Server 8.1.2 contains an authenticated remote code execution vulnerability in the session serialization mechanism that allows authenticated administrators to inject arbitrary Lua code through the domain admin mydirectory field. Attackers can exploit unsafe serialization of session values into Lua source code without proper escaping of closing delimiters, causing the injected code to be executed when the poisoned session is loaded via loadfile().

Basic Information

ID CVE-2026-44403
Source VulnCheck
Published May 12, 2026 at 20:43
Modified May 12, 2026 at 21:12

Affected Product

Vendor Wing FTP Server
Product Wing FTP Server
Version 8.1.2
Affected Versions Wing FTP Server Wing FTP Server 8.1.2

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.