Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2026-22679 — Unauthenticated RCE exploit and detection scanner for Weaver E-cology, targeting the dubboApi debug endpoint. Includes PoC, Nmap NSE script, and remediation guidance. | Kitploit
Tools/GitHubGitHub/keraattin/cve-2026-22679
ReconnaissanceVulnerability ScannersVulnerability AnalysisExploitationWeb SecurityPenetration Testing
GitHubkeraattin/cve-2026-22679

CVE-2026-22679

Unauthenticated RCE exploit and detection scanner for Weaver E-cology, targeting the dubboApi debug endpoint. Includes PoC, Nmap NSE script, and remediation guidance.

View Repository
5205 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2026-22679: Weaver E-cology Unauthenticated RCE via dubboApi Debug Endpoint

CVE ID CVSS Score CWE Classification Weaver E-cology

TL;DR

Weaver E-cology 10.0 (prior to build 20260312) contains a critical unauthenticated remote code execution vulnerability in the /papi/esearch/data/devops/dubboApi/debug/method endpoint. Attackers can inject arbitrary commands through the interfaceName and methodName POST parameters without authentication, achieving complete system compromise. Active exploitation detected since 2026-03-31 by Shadowserver Foundation.

Quick Risk: CVSS 9.3 - Completely unauthenticated, no user interaction required, network accessible endpoint leading directly to code execution.


Table of Contents

  1. Quick Facts
  2. What is Weaver E-cology
  3. Vulnerability Deep Dive
    • Root Cause Analysis
    • Attack Flow Diagram
    • Vulnerable Endpoint Details
  4. Impact Analysis
  5. Affected Versions
  6. Detection
    • Python Scanner
    • Nmap NSE Script
  7. Indicators of Compromise
  8. Remediation
  9. References
  10. Author

Quick Facts

AspectDetails
CVE IDCVE-2026-22679
CVSS Score9.3 (Critical)
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWECWE-94 (Code Injection)
VendorWeaver (Fanwei)
ProductE-cology 10.0
Vulnerability TypeUnauthenticated Remote Code Execution (RCE)
Affected Endpoint/papi/esearch/data/devops/dubboApi/debug/method
Attack VectorNetwork / HTTP POST
Authentication RequiredNone
Versions Affected10.0 versions prior to build 20260312
Fixed VersionBuild 20260312 (released 2026-03-12)
Active ExploitationSince 2026-03-31 (Shadowserver Foundation)
Patch MethodComplete removal of vulnerable endpoint

What is Weaver E-cology?

Weaver E-cology is one of China's most widely deployed enterprise OA (Office Automation) and collaboration platforms. Developed by Fanwei Group, it is extensively used across:

  • Government Agencies: Central and provincial government departments
  • Large Enterprises: Fortune 500 companies and state-owned enterprises
  • Financial Institutions: Banks, insurance companies, and investment firms
  • Educational Institutions: Universities and research organizations across Asia

Key Capabilities

E-cology provides comprehensive enterprise solutions including:

  • Document Management: Secure storage, versioning, and retrieval of enterprise documents
  • Workflow Automation: Business process automation, approval chains, and task routing
  • Human Resources: Employee management, payroll integration, and organizational hierarchies
  • Collaboration Tools: Email, instant messaging, calendars, and project management
  • Portal Services: Customizable enterprise portals and dashboards

Deployment Footprint

E-cology deployments typically range from hundreds to thousands of users per organization. The platform is a critical infrastructure component for many organizations, making vulnerabilities in it extremely high impact.


Vulnerability Deep Dive

Root Cause Analysis

The vulnerability exists in the dubboApi debug endpoint, which was likely left accessible for development and troubleshooting purposes. The endpoint allows direct invocation of arbitrary methods through the Dubbo RPC framework without proper input validation or authentication checks.

Vulnerable Code Pattern:

POST /papi/esearch/data/devops/dubboApi/debug/method HTTP/1.1
Host: target.com
Content-Type: application/json

{
  "interfaceName": "com.weaver.rpc.InvokeCommand",
  "methodName": "executeCommand",
  "parameters": ["id", "whoami", "cat /etc/passwd"]
}

The application directly processes these parameters and passes them to RPC command execution helpers without:

  • Authentication verification
  • Input validation/sanitization
  • Method whitelist enforcement
  • Parameter type checking

This allows attackers to specify arbitrary Dubbo interface methods that execute system commands.

Attack Flow Diagram

Internet Attacker
    |
    | Sends unauthenticated POST request
    | with malicious interfaceName/methodName
    v
Weaver E-cology HTTP Server (port 80/443)
    |
    | No authentication check
    | No authorization validation
    v
/papi/esearch/data/devops/dubboApi/debug/method endpoint
    |
    | Direct parameter pass-through to Dubbo RPC layer
    v
Dubbo RPC Framework (unvalidated interface invocation)
    |
    | Resolves arbitrary interface methods
    | Attacker-controlled method name injection
    v
Command Execution Helpers (vulnerable classes)
    |
    | Direct OS command execution via Runtime.exec()
    | or similar OS command invocation mechanisms
    v
System Command Execution
    |
    | Complete code execution as Weaver service user
    | (typically root or high-privilege account)
    |
    +-> Read sensitive files (/etc/passwd, configs)
    +-> Execute arbitrary binaries
    +-> Create reverse shells
    +-> Exfiltrate data
    +-> Establish persistence
    v
Complete System Compromise

Vulnerable Endpoint Details

Endpoint Path: /papi/esearch/data/devops/dubboApi/debug/method

HTTP Method: POST

Required Authentication: None (zero authentication)

Required Headers: Standard HTTP headers (no special tokens or cookies required)

Request Body Parameters:

ParameterTypeDescriptionExample
interfaceNameStringRPC interface class name (attacker-controlled)com.weaver.rpc.InvokeCommand
methodNameStringMethod name to invoke (attacker-controlled)executeCommand
parametersArrayMethod parameters passed directly to execution logic["id"]

Endpoint Exposure Flow:

Weaver Deployment Architecture
===============================

Internet
  |
  v
Firewall (often misconfigured or open for "accessibility")
  |
  v
Web Server (port 80/443)
  |
  +--------> HTTP Request to any path
  |
  v
Route Dispatcher
  |
  +---> /login/Login.jsp > Requires authentication
  |
  +---> /wui/index.html > Requires authentication
  |
  +---> /papi/esearch/data/devops/dubboApi/debug/method
           |
           +---> UNPROTECTED - No authentication check!
                 |
                 v
           Dubbo RPC Invoker (unrestricted method invocation)
                 |
                 v
           OS Command Execution
                 |
                 v
           System Compromise (RCE as web user)

Typical Weaver Deployment Architecture

Corporate Network
=================

Internet > Firewall (port 80/443 open for E-cology)
              |
              v
        Load Balancer (optional)
              |
    +---------+---------+
    |         |         |
    v         v         v
 Node1      Node2     Node3
  Web        Web       Web
 Server      Server    Server
  |          |         |
  +----------+----+----+
               |
               v
         Shared Storage
         (Documents/Config)
               |
               v
         Database Server
         (MySQL/Oracle)
Download Tool