CVE-2022-50934
Wing FTP Server vulnerability analysis and mitigation

Overview

CVE-2022-50934 was initially described as an authenticated remote code execution vulnerability in Wing FTP Server versions 4.3.8 and below, allegedly allowing attackers to execute arbitrary PowerShell commands through the admin interface via crafted Lua script payloads. However, this CVE has been officially rejected — it was withdrawn by its CNA (VulnCheck) after further investigation determined it was not a security issue. The CVE was submitted on January 13, 2026, and rejected on January 14, 2026. No valid CVSS score is assigned by NVD due to the rejection status (NVD).

Technical details

Prior to rejection, the vulnerability was described as a code injection issue (CWE-94) in Wing FTP Server's admin interface, where an authenticated attacker could supply a crafted Lua script containing base64-encoded PowerShell commands to achieve remote code execution. The attack vector was network-based, requiring low-privilege authentication with no user interaction. Upon rejection by VulnCheck (the CNA), all associated CVSS scores, CWE classifications, and references were formally removed from the NVD record, as the behavior was determined not to constitute a security vulnerability (NVD).

Impact

Because CVE-2022-50934 has been officially rejected and determined not to be a security issue, there is no confirmed security impact to report. The originally claimed impact — full server compromise, data exfiltration, and reverse shell establishment — was not validated and was retracted by the CNA (NVD).

Exploitability

CVE-2022-50934 is a rejected CVE with no confirmed exploitability. An Exploit-DB entry (50720) was initially referenced but was removed from the NVD record upon rejection. The EPSS score is 0.00204 (very low), and there is no evidence of in-the-wild exploitation or CISA KEV catalog inclusion. The CVE should not be treated as an actionable vulnerability (NVD).

Mitigation and workarounds

As CVE-2022-50934 has been rejected and determined not to be a security issue, no specific patch or mitigation is required for this CVE. Organizations using Wing FTP Server should continue to follow general security best practices: restrict admin interface access via firewall rules, enforce strong authentication, and keep software updated to the latest vendor-supported version (NVD).

Community reactions

The CVE was briefly published by VulnCheck on January 13, 2026, and retracted the following day after the CNA determined it did not represent a genuine security issue. The rapid rejection cycle — less than 24 hours from publication to withdrawal — generated minimal community discussion. No significant vendor statements, researcher commentary, or media coverage was associated with this CVE (NVD).

Additional resources


SourceThis report was generated using AI

Related Wing FTP Server vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-44403HIGH8.6
  • Wing FTP Server logoWing FTP Server
  • cpe:2.3:a:wftpserver:wing_ftp_server
NoYesMay 12, 2026
CVE-2020-37032HIGH8.6
  • Wing FTP Server logoWing FTP Server
  • cpe:2.3:a:wftpserver:wing_ftp_server
NoYesJan 30, 2026
CVE-2019-25267HIGH8.5
  • Wing FTP Server logoWing FTP Server
  • cpe:2.3:a:wftpserver:wing_ftp_server
NoYesFeb 05, 2026
CVE-2020-37079MEDIUM5.1
  • Wing FTP Server logoWing FTP Server
  • cpe:2.3:a:wftpserver:wing_ftp_server
NoYesFeb 07, 2026
CVE-2022-50934NONEN/A
  • Wing FTP Server logoWing FTP Server
  • cpe:2.3:a:wftpserver:wing_ftp_server
NoYesJan 13, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management