NVD Vulnerability Detail
Search Exploit, PoC
CVE-2026-44403
Summary

Wing FTP Server before 8.1.3 contains an authenticated remote code execution vulnerability in the session serialization mechanism that allows authenticated administrators to inject arbitrary Lua code through the domain admin mydirectory field. Attackers can exploit unsafe serialization of session values into Lua source code without proper escaping of closing delimiters, causing the injected code to be executed when the poisoned session is loaded via loadfile().

Publication Date May 13, 2026, 6:16 a.m.
Registration Date May 15, 2026, 4:18 a.m.
Last Update May 14, 2026, 11:50 p.m.
CVSS3.1 : HIGH
スコア 7.2
Vector CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
攻撃元区分(AV) ネットワーク
攻撃条件の複雑さ(AC)
攻撃に必要な特権レベル(PR)
利用者の関与(UI) 不要
影響の想定範囲(S) 変更なし
機密性への影響(C)
完全性への影響(I)
可用性への影響(A)
Affected software configurations
Configuration1 or higher or less more than less than
cpe:2.3:a:wftpserver:wing_ftp_server:*:*:*:*:*:*:*:* 8.1.3
Related information, measures and tools
Common Vulnerabilities List