CVE-2026-44403 is an authenticated remote code execution vulnerability in Wing FTP Server 8.1.2. The flaw resides in the product's session serialization mechanism, where session values are serialized into Lua source code and later processed via loadfile(). An authenticated administrator can supply a crafted value in the domain admin mydirectory field that injects arbitrary Lua code because closing delimiters are not properly escaped during serialization. When the poisoned session is subsequently loaded, the injected Lua code is executed.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
This repository is a small, focused exploit PoC for an authenticated RCE in Wing FTP Server v8.1.2 caused by unsafe Lua session serialization and subsequent execution via loadfile(). It contains two files: a README describing the vulnerability and exploitation chain, and a Python script (session_poisoning_poc.py) that automates exploitation. The exploit targets the Wing FTP web admin interface. It logs in with valid full administrator credentials, then abuses the vulnerable admin-management functionality to create a domain admin account whose mydirectory/basefolder field contains a crafted Lua breakout sequence using ']]<lua>--'. When that poisoned domain admin logs in, the malicious basefolder is copied into session variables such as admin_basefolder and admin_nowpath. On a later request, Wing FTP reloads the session file as Lua code, causing the injected payload to execute with the privileges of the Wing FTP service account (SYSTEM on Windows or root on Linux, per the README). The Python exploit is operational rather than just demonstrative: it supports a demo mode and an exploit mode, uses requests.Session for HTTP state handling, disables TLS verification warnings, authenticates to /service_login.html, and attempts to create a poisoned admin through /service_add_admin.html. The script’s default payload is a Lua os.execute command that writes the output of whoami to C:\wingftp_pwned.txt, though the README also shows similar proof-file payloads such as C:\proof.txt and C:\wingftp_rce_proof.txt. The exploit relies on the target exposing the admin panel, typically on port 5466, and on the attacker having sufficient admin privileges to add or modify domain admins. Overall purpose: authenticated remote code execution through session poisoning, not detection. The repository does not appear to belong to a larger exploit framework.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.