Briefing

Weaver E-cology 10.0 Suffers Critical Remote Code Execution Bug

security
by Bill Toulas · CVE-2026-22679

Patch Weaver E‑Cology 10.0 to build 20260312 immediately to eliminate the exposed debug endpoint and stop RCE.

What to do now

Patch to build 20260312 immediately; verify the debug endpoint is removed; monitor logs for RCE attempts.

Summary

A critical remote code execution flaw, identified as CVE‑2026‑22679, has been discovered in the Weaver (Fanwei) E‑cology 10.0 office automation platform. The vulnerability, which carries a CVSS score of 9.8, allows unauthenticated attackers to run arbitrary code through the “/papi/esearch/data/devops/” endpoint. Security researchers reported that the flaw has already been exploited in the wild since March, giving attackers full control of affected systems and the potential to exfiltrate data.

Weaver E‑cology is a Chinese enterprise software suite used by businesses for document management, workflow automation and collaboration. The flaw affects all 10.0 releases prior to the 20260312 build, which removes the vulnerable endpoint and strengthens authentication checks. Weaver’s support team issued a security advisory outlining the affected versions and the steps required to remediate the issue. The advisory recommends disabling the /papi/esearch/data/devops/ endpoint on legacy installations until the patch is applied.

In response, the vendor has released the 20260312 update, which eliminates the vulnerable endpoint and hardens authentication. Users are urged to upgrade immediately or apply the vendor‑issued hotfix. The advisory also advises organizations to verify their current version, monitor logs for suspicious activity related to the endpoint, and conduct a full security audit to ensure no other legacy endpoints remain exposed. The incident underscores the importance of timely patch management in enterprise software, especially for systems that handle sensitive business data.

The exploitation of this vulnerability could lead to complete system compromise, data theft, and disruption of critical business processes. Companies that rely on Weaver E‑cology are advised to act swiftly, apply the latest patch, and review their overall security posture to prevent similar incidents in the future.

Key changes

  • CVE‑2026‑22679 permits unauthenticated remote code execution via an exposed debug API endpoint.
  • Affected builds: Weaver E‑Cology 10.0 prior to March 12 2026.
  • Attackers used PowerShell payloads and file‑less scripts to download and execute code.
  • The vendor’s fix (build 20260312) removes the debug endpoint entirely.
  • No alternative mitigations are available; upgrading is mandatory.
  • Exploit activity lasted roughly one week, comprising five distinct phases.
  • No persistence was achieved; attackers did not establish a long‑term session.
  • The RCE endpoint was parented by java.exe (Weaver’s Tomcat‑bundled JVM).

Affects

enterprise

Source angles · 2 perspectives

Bleeping Computer
Independent angle

Weaver E-cology critical bug exploited in attacks since March

Open
The Hacker News
Independent angle

CVE-2026-22679: Critical RCE Vulnerability in Weaver E-cology 10.0

Open

Customer impact

Analyzing matches…

Ask about this story

Impact on an agency? Which customers? Compare historically Risks of waiting