
Unauthenticated RCE exploit and detection scanner for Weaver E-cology, targeting the dubboApi debug endpoint. Includes PoC, Nmap NSE script, and remediation guidance.
Weaver E-cology 10.0 (prior to build 20260312) contains a critical unauthenticated remote code execution vulnerability in the /papi/esearch/data/devops/dubboApi/debug/method endpoint. Attackers can inject arbitrary commands through the interfaceName and methodName POST parameters without authentication, achieving complete system compromise. Active exploitation detected since 2026-03-31 by Shadowserver Foundation.
Quick Risk: CVSS 9.3 - Completely unauthenticated, no user interaction required, network accessible endpoint leading directly to code execution.
| Aspect | Details |
|---|---|
| CVE ID | CVE-2026-22679 |
| CVSS Score | 9.3 (Critical) |
| CVSS Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| CWE | CWE-94 (Code Injection) |
| Vendor | Weaver (Fanwei) |
| Product | E-cology 10.0 |
| Vulnerability Type | Unauthenticated Remote Code Execution (RCE) |
| Affected Endpoint | /papi/esearch/data/devops/dubboApi/debug/method |
| Attack Vector | Network / HTTP POST |
| Authentication Required | None |
| Versions Affected | 10.0 versions prior to build 20260312 |
| Fixed Version | Build 20260312 (released 2026-03-12) |
| Active Exploitation | Since 2026-03-31 (Shadowserver Foundation) |
| Patch Method | Complete removal of vulnerable endpoint |
Weaver E-cology is one of China's most widely deployed enterprise OA (Office Automation) and collaboration platforms. Developed by Fanwei Group, it is extensively used across:
E-cology provides comprehensive enterprise solutions including:
E-cology deployments typically range from hundreds to thousands of users per organization. The platform is a critical infrastructure component for many organizations, making vulnerabilities in it extremely high impact.
The vulnerability exists in the dubboApi debug endpoint, which was likely left accessible for development and troubleshooting purposes. The endpoint allows direct invocation of arbitrary methods through the Dubbo RPC framework without proper input validation or authentication checks.
Vulnerable Code Pattern:
POST /papi/esearch/data/devops/dubboApi/debug/method HTTP/1.1
Host: target.com
Content-Type: application/json
{
"interfaceName": "com.weaver.rpc.InvokeCommand",
"methodName": "executeCommand",
"parameters": ["id", "whoami", "cat /etc/passwd"]
}
The application directly processes these parameters and passes them to RPC command execution helpers without:
This allows attackers to specify arbitrary Dubbo interface methods that execute system commands.
Internet Attacker
|
| Sends unauthenticated POST request
| with malicious interfaceName/methodName
v
Weaver E-cology HTTP Server (port 80/443)
|
| No authentication check
| No authorization validation
v
/papi/esearch/data/devops/dubboApi/debug/method endpoint
|
| Direct parameter pass-through to Dubbo RPC layer
v
Dubbo RPC Framework (unvalidated interface invocation)
|
| Resolves arbitrary interface methods
| Attacker-controlled method name injection
v
Command Execution Helpers (vulnerable classes)
|
| Direct OS command execution via Runtime.exec()
| or similar OS command invocation mechanisms
v
System Command Execution
|
| Complete code execution as Weaver service user
| (typically root or high-privilege account)
|
+-> Read sensitive files (/etc/passwd, configs)
+-> Execute arbitrary binaries
+-> Create reverse shells
+-> Exfiltrate data
+-> Establish persistence
v
Complete System Compromise
Endpoint Path: /papi/esearch/data/devops/dubboApi/debug/method
HTTP Method: POST
Required Authentication: None (zero authentication)
Required Headers: Standard HTTP headers (no special tokens or cookies required)
Request Body Parameters:
| Parameter | Type | Description | Example |
|---|---|---|---|
interfaceName | String | RPC interface class name (attacker-controlled) | com.weaver.rpc.InvokeCommand |
methodName | String | Method name to invoke (attacker-controlled) | executeCommand |
parameters | Array | Method parameters passed directly to execution logic | ["id"] |
Endpoint Exposure Flow:
Weaver Deployment Architecture
===============================
Internet
|
v
Firewall (often misconfigured or open for "accessibility")
|
v
Web Server (port 80/443)
|
+--------> HTTP Request to any path
|
v
Route Dispatcher
|
+---> /login/Login.jsp > Requires authentication
|
+---> /wui/index.html > Requires authentication
|
+---> /papi/esearch/data/devops/dubboApi/debug/method
|
+---> UNPROTECTED - No authentication check!
|
v
Dubbo RPC Invoker (unrestricted method invocation)
|
v
OS Command Execution
|
v
System Compromise (RCE as web user)
Corporate Network
=================
Internet > Firewall (port 80/443 open for E-cology)
|
v
Load Balancer (optional)
|
+---------+---------+
| | |
v v v
Node1 Node2 Node3
Web Web Web
Server Server Server
| | |
+----------+----+----+
|
v
Shared Storage
(Documents/Config)
|
v
Database Server
(MySQL/Oracle)