Briefing

Weaver E-cology 10.0 RCE Vulnerability (CVE-2026-22679) Actively Exploited

security
by [email protected] (The Hacker News) · CVE-2026-22679

Patch Weaver E-cology to version 20260312 or later immediately to eliminate the unauthenticated RCE vulnerability (CVE-2026-22679).

What to do now

Patch Weaver E-cology to version 20260312 or later immediately.

Summary

A critical remote code execution vulnerability (CVE-2026-22679) has been discovered in Weaver (Fanwei) E-cology, an enterprise office automation and collaboration platform. The flaw allows unauthenticated attackers to execute arbitrary code via the /papi/esearch/data/devops/ endpoint. It carries a CVSS score of 9.8 and is actively exploited in the wild.

The vulnerability affects all Weaver E-cology 10.0 releases prior to the 20260312 build. A patch was released in version 20260312 that removes the insecure endpoint and hardens authentication checks. Clients using older builds are at risk of remote compromise without any user interaction. Immediate remediation is required to prevent potential data exfiltration and system takeover.

Key changes

  • CVE-2026-22679 identified
  • CVSS score 9.8
  • Unauthenticated RCE via /papi/esearch/data/devops/
  • Affects Weaver E-cology 10.0 before 20260312
  • Active exploitation observed in the wild
  • Patch available in version 20260312
  • Affected component: /papi/esearch/data/devops/
  • Remediation: upgrade to 20260312 or later

Affects

enterprise

Customer impact

Analyzing matches…

Ask about this story

Impact on an agency? Which customers? Compare historically Risks of waiting