Junglewise Threat Intelligence

CVE-2026-51368: Beijing Tongtech TongWeb HttpInvokerServiceExporter deserialization RCE

CVE-2026-51368 · Severity: critical · CVSS 9.8 · Published 2026-08-25

Executive brief

TongWeb is an application server used in enterprise environments. The server exposes an administrative console and cluster management interface that deserializes untrusted data without validation, allowing a remote attacker to execute arbitrary code on the server with full system privileges. This can lead to complete compromise of the system and any services or data it hosts.

Technical details

The vulnerability is a Java object deserialization flaw (CWE-502) in Spring's HttpInvokerServiceExporter component exposed at /console/service and /heimdall/service endpoints on the default administration port 9060. The endpoints accept HTTP POST requests and deserialize the request body using ObjectInputStream.readObject() without authentication or input validation. A network attacker can craft a malicious serialized Java object using the CommonsBeanutils1 gadget chain (enabled by commons-beanutils-1.8.0.jar on the classpath) to achieve remote code execution with the privileges of the TongWeb process (typically root). The vulnerability requires no authentication, user interaction, or special network access—only network reachability to port 9060.

Affected products

  • Beijing Tongtech Co., Ltd. TongWeb 7.0 (confirmed on 7.0.24; other 7.0.x likely affected)

Timeline

  • 2026-08-25: disclosed
  • other: Public PoC available on GitHub (gist by loseyourself1)

References