Weaver E-cology 10.0 RCE Vulnerability (CVE-2026-22679) Actively Exploited
Patch Weaver E-cology to version 20260312 or later immediately to eliminate the unauthenticated RCE vulnerability (CVE-2026-22679).
Patch Weaver E-cology to version 20260312 or later immediately.
Summary
A critical remote code execution vulnerability (CVE-2026-22679) has been discovered in Weaver (Fanwei) E-cology, an enterprise office automation and collaboration platform. The flaw allows unauthenticated attackers to execute arbitrary code via the /papi/esearch/data/devops/ endpoint. It carries a CVSS score of 9.8 and is actively exploited in the wild.
The vulnerability affects all Weaver E-cology 10.0 releases prior to the 20260312 build. A patch was released in version 20260312 that removes the insecure endpoint and hardens authentication checks. Clients using older builds are at risk of remote compromise without any user interaction. Immediate remediation is required to prevent potential data exfiltration and system takeover.
Key changes
- CVE-2026-22679 identified
- CVSS score 9.8
- Unauthenticated RCE via /papi/esearch/data/devops/
- Affects Weaver E-cology 10.0 before 20260312
- Active exploitation observed in the wild
- Patch available in version 20260312
- Affected component: /papi/esearch/data/devops/
- Remediation: upgrade to 20260312 or later