Threat reportVulnerabilityTL-2026-0455
Weaver E-cology Unauthenticated RCE (CVE-2026-22679) — Active Exploitation Since Mid-March 2026 via dubboApi Debug Endpoint
Weaver E-cology Unauthenticated RCE (CVE-2026-22679) (TL-2026-0455), also tracked as Weaver E-cology dubboApi RCE, is a critical-severity software vulnerability scored CVSS 9.8, first published 2026-05-04. It has no confirmed attribution, affects Shanghai Weaver Network (Fanwei / 泛微) E-cology 10.0, references 1 CVE (CVE-2026-22679), maps to 20 MITRE ATT&CK techniques (T1016, T1027, T1027.010), and is covered by 9 detection rules and 18 indicators of compromise.
- CVSS
- 9.8/10Critical
- CVEs
- 1Referenced vulnerabilities
- Techniques
- 20MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 18Indicators of compromise
Key facts for TL-2026-0455
- Threat ID
- TL-2026-0455
- Also known as
- Weaver E-cology dubboApi RCE, Fanwei E-cology Debug Endpoint RCE, E-cology 10.0 Unauthenticated RCE, VulnCheck VC-CVE-2026-22679
- Severity
- CRITICAL
- CVSS
- 9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
- Status
- ACTIVE
- Category
- VULNERABILITY
- First published
- Last reviewed
- Attribution confidence
- NONE
- Motivation
- UNKNOWN
- Target sectors
- government, financial, banking, insurance, education, higher-education, manufacturing, energy, telecommunications, state-owned-enterprise
- Target regions
- China, Hong Kong, Taiwan, Asia-Pacific
- Detection rules
- 9
- Indicators of compromise
- 18
Malware and tooling in Weaver E-cology Unauthenticated RCE (CVE-2026-22679)
Malware and tooling: Goby
How Weaver E-cology Unauthenticated RCE (CVE-2026-22679) works
CVE-2026-22679 is a critical (CVSS 9.8) unauthenticated remote code execution flaw in Weaver (Fanwei) E-cology 10.0 builds prior to 20260312, caused by an exposed Dubbo RPC debug endpoint at /papi/esearch/data/devops/dubboApi/debug/method that accepts attacker-controlled interfaceName and methodName POST parameters and routes them to backend command-execution helpers without authentication or input validation. Vega researchers documented in-the-wild exploitation beginning approximately 2026-03-17 (~five days after the silent vendor patch on 2026-03-12 and roughly two weeks before public disclosure on 2026-03-31), with attackers using Goby-linked ICMP callbacks for capability checks, multiple PowerShell-based fileless payload downloads, an MSI installer named fanwei0324.msi, and reconnaissance commands (whoami, ipconfig, tasklist) parented by the Tomcat-bundled java.exe service process. Shadowserver Foundation independently confirmed scanning and exploitation starting 2026-03-31 UTC, and the issue affects organizations across Chinese government, financial services, large enterprise, and higher education sectors that depend on this widely deployed OA platform.
## Overview
CVE-2026-22679 is an unauthenticated remote code execution vulnerability affecting Weaver E-cology 10.0 (all builds prior to 20260312). E-cology, developed by Shanghai Weaver Network Co. Ltd. (泛微 / Fanwei), is one of the most widely deployed enterprise office automation (OA) and collaboration platforms in mainland China, used across government agencies, state-owned enterprises, banks and insurance firms, large private corporations, and universities. The product bundles document management, workflow automation, HR, messaging, calendaring, and portal services on top of an embedded Tomcat/JBoss container running a Java application with the Apache Dubbo RPC framework underneath.
The vulnerability resides in a development/diagnostics endpoint that was inadvertently shipped to production: `/papi/esearch/data/devops/dubboApi/debug/method`. This endpoint accepts unauthenticated HTTP POST requests and parses two attacker-controlled string parameters — `interfaceName` (a fully-qualified Dubbo interface class) and `methodName` (the method to invoke on that interface) — alongside a `parameters` array. The handler then resolves the requested interface/method via the Dubbo RPC layer and invokes it with the supplied parameters. Because the dispatch logic enforces no authentication, no allow-list of safe interfaces or methods, no parameter type checking, and no input sanitization, an attacker can pivot the endpoint into arbitrary OS command execution by selecting a command-execution helper class exposed to the RPC registry. The resulting child process inherits the privileges of the Weaver service account, which on Windows installations is typically a SYSTEM-level service account and on Linux installations is frequently root or a high-privileged service user.
## Root Cause and Exploitation Mechanics
The vendor patch released on 2026-03-12 simply removes the entire `/papi/esearch/data/devops/dubboApi/debug/method` route — there is no allow-list refactor or authentication wrapper, indicating the endpoint had no production purpose. NVD primary CWE classification is CWE-306 (Missing Authentication for Critical Function); third-party analysis additionally maps the issue to CWE-94 (Improper Control of Generation of Code) because attacker input directly drives RPC method selection.
An exploitation request looks like:
``` POST /papi/esearch/data/devops/dubboApi/debug/method HTTP/1.1 Host: <target> Content-Type: application/json
{"interfaceName": "com.weaver.rpc.<command-helper-class>", "methodName": "<exec-method>", "parameters": ["<command>", "<arg1>", "<arg2>"]} ```
Because the request is a single unauthenticated POST and the response surface is shaped like a routine API call, exploitation traffic blends easily into normal application logs unless defenders explicitly look for the path.
## Observed Campaign (Vega Threat Intelligence)
Vega documented at least one extended campaign lasting roughly a week per targeted organization with several distinct phases. Each campaign began approximately 2026-03-17, only five days after Weaver's silent patch — a tempo that strongly suggests patch-diff exploit development by a capable, organized actor that monitors the vendor's official patch portal (https://www.weaver.com.cn/cs/securityDownload.html).
Phase 1 — Capability Probe: attackers issued ICMP `ping` commands from the Java process to a Goby-linked callback infrastructure to confirm RCE primitive worked end-to-end. Goby is a Chinese-language vulnerability scanner heavily used by both red teams and threat actors operating in the Sinophone space.
Phase 2 — PowerShell Payload Download: attackers issued obfuscated and fileless PowerShell commands (e.g., `powershell.exe -nop -w hidden -enc <base64>` style) to fetch follow-on payloads from external infrastructure. These were repeatedly blocked by endpoint defenses on the targets Vega observed.
Phase 3 — MSI Installer Deployment: after PowerShell failures, attackers attempted to deliver a target-aware MSI installer named `fanwei0324.msi` (the file name encodes the Chinese transliteration of Weaver — "Fanwei" / 泛微 — plus the date 03-24, suggesting build-naming discipline by the operator). The MSI failed to execute properly on the observed targets and no follow-on persistence was established.
Phase 4 — Reversion to Fileless RCE: after MSI failures, attackers cycled back to the dubboApi endpoint and used obfuscated PowerShell to repeatedly fetch remote scripts directly into memory.
Throughout all phases, recon commands `whoami`, `ipconfig`, and `tasklist` were observed parented by `java.exe` (the bundled Tomcat process). Vega assesses that despite repeated successful RCE, the actor never established persistent C2 — the campaign reads as an opportunistic mass-exploitation effort that reverted to recon-only when payload delivery failed, rather than a targeted intrusion with prepared tooling.
## Independent Confirmation
Shadowserver Foundation confirmed exploitation traffic against honeypots and customer telemetry beginning 2026-03-31 UTC, providing an independent floor on the active exploitation start date. VulnCheck published a formal advisory (VC-CVE-2026-22679) and the CVE was assigned by VulnCheck (disclosure@vulncheck.com) and published on NVD on 2026-04-07. BleepingComputer surfaced the campaign publicly on 2026-05-04.
## Affected Versions and Patch
E-cology 10.0 builds prior to 20260312 are vulnerable. The fixed build is 20260312, released 2026-03-12 as a security-only update available from https://www.weaver.com.cn/cs/securityDownload.html. The vendor advisory does not list workarounds — upgrading is the only recommended remediation. Older E-cology versions (9.x, 8.x, 7.x) have not been confirmed vulnerable but should be assessed against the vendor security portal which publishes per-line patches.
## Risk Profile
This vulnerability is high-impact because: (1) E-cology is internet-exposed at many Chinese organizations to support remote employee access; (2) the endpoint is unauthenticated with a deterministic, low-complexity exploit path; (3) the affected service typically runs with privileged service account credentials granting full host compromise on a single request; (4) public PoC scanners (Python, Nmap NSE) are now available, lowering the bar for opportunistic actors; (5) Weaver E-cology stores HR data, financial records, contracts, and signed approvals — making it both a high-value initial-access pivot and a high-value data target in its own right.
MITRE ATT&CK techniques used in TL-2026-0455
Discovery
T1016 System Network Configuration Discovery; T1033 System Owner/User Discovery; T1057 Process Discovery; T1082 System Information Discovery
Defense Evasion
T1027 Obfuscated Files or Information; T1027.010 Obfuscated Files or Information: Command Obfuscation; T1218.007 System Binary Proxy Execution: Msiexec; T1620 Reflective Code Loading
Execution
T1059.001 Command and Scripting Interpreter: PowerShell; T1059.003 Command and Scripting Interpreter: Windows Command Shell; T1204 User Execution; T1569.002 System Services: Service Execution
Command and Control
T1071.001 Application Layer Protocol: Web Protocols; T1095 Non-Application Layer Protocol; T1105 Ingress Tool Transfer
Initial Access
T1190 Exploit Public-Facing Application
Resource Development
T1583 Acquire Infrastructure; T1608.001 Stage Capabilities: Upload Malware
Reconnaissance
Affected products and versions in Weaver E-cology Unauthenticated RCE (CVE-2026-22679)
- Shanghai Weaver Network (Fanwei / 泛微) — E-cology 10.0
Vulnerable versions: all builds prior to 20260312
Fixed in: 20260312; later monthly rollups - Shanghai Weaver Network (Fanwei / 泛微) — E-cology 9.0 / 8.0 / 7.0
Vulnerable versions: status unconfirmed — consult Weaver security portal per-line advisories
Fixed in: E9.0 build v10.79 (2025-09-25) and later
Remediation for Weaver E-cology Unauthenticated RCE (CVE-2026-22679)
Patches
- Weaver E-cology 10.0 build 20260312 (released 2026-03-12) — security-only update available from official Weaver portal
- Subsequent monthly security rollups — apply latest available build
Immediate actions
- Block all HTTP/S requests to /papi/esearch/data/devops/dubboApi/debug/method at WAF, reverse proxy, or web server (nginx: location /papi/esearch/data/devops/dubboApi { return 403; })
- Restrict E-cology administrative interfaces to internal networks only — remove direct internet exposure where possible and require VPN/bastion access
- Hunt web access logs for POST requests to /papi/esearch/data/devops/dubboApi/debug/method since 2026-03-12; treat any hit as confirmed exploitation attempt
- Hunt for child processes of Tomcat java.exe spawning powershell.exe, cmd.exe, whoami.exe, ipconfig.exe, tasklist.exe, or msiexec.exe with fanwei0324.msi argument
- Block known indicator file name fanwei0324.msi via EDR file-write rules and AV signatures
Workarounds
- WAF/reverse-proxy rule blocking the vulnerable URI path is an effective compensating control until patch can be applied
- Disable internet exposure of E-cology entirely if patching cannot be scheduled within the next 24-48 hours
Longer-term hardening
- Apply Weaver E-cology build 20260312 or later from https://www.weaver.com.cn/cs/securityDownload.html — the patch removes the vulnerable endpoint entirely
- Deploy EDR with behavioral detection capable of flagging Java service-account spawning interactive shells or download utilities
- Implement network segmentation around E-cology hosts so that even on RCE the Java service cannot pivot to AD domain controllers, file shares, or financial systems
- Add WAF rules that alert on any access to URI paths containing /devops/dubboApi or /debug/method regardless of HTTP method
- Establish a recurring vendor-patch monitoring process for Weaver security portal — patch within 72 hours of release given demonstrated patch-diff exploitation tempo
- For organizations subject to Chinese MLPS / cybersecurity regulatory regimes, document this incident class in the annual cybersecurity self-assessment
CVEs associated with Weaver E-cology Unauthenticated RCE (CVE-2026-22679)
Weaknesses (CWE) in Weaver E-cology Unauthenticated RCE (CVE-2026-22679)
Timeline of Weaver E-cology Unauthenticated RCE (CVE-2026-22679)
- Weaver releases E-cology 10.0 build 20260312 to its security download portal as a silent fix that fully removes the /papi/esearch/data/devops/dubboApi/debug/method route. No public CVE assignment or advisory accompanies the patch.
- Vega Threat Intelligence observes the first in-the-wild exploitation, approximately five days after the silent vendor patch — a tempo consistent with patch-diff reverse engineering by an organized actor monitoring the Weaver security portal.
- Attackers stage a target-aware MSI installer named fanwei0324.msi (Fanwei = Weaver romanized; 0324 = March 24), suggesting active build cadence on operator infrastructure.
- Shadowserver Foundation independently records the first exploitation telemetry against honeypots and customer sensors at 2026-03-31 UTC, providing an authoritative floor on widespread scanning.
- VulnCheck assigns and publishes CVE-2026-22679 with a formal advisory; NVD entry goes live with CVSS v3.1 9.8 / CVSS v4.0 9.3 and CWE-306 mapping.
- Qi'anxin Threat Intelligence Center publishes a Chinese-language advisory (notice-detail/1760) covering CVE-2026-22679 for domestic defenders.
- Detection-only Python scanner and Nmap NSE script released on GitHub (keraattin/CVE-2026-22679) — no exploitation primitive, but the endpoint signature is now public, lowering the bar for opportunistic actors.
- NVD moves CVE-2026-22679 from 'Awaiting Analysis' to 'Analyzed', confirming CPE matches and CVSS metrics.
- BleepingComputer publishes the Vega-sourced narrative covering the campaign timeline, payload chain (Goby → PowerShell → fanwei0324.msi), and reconnaissance commands — driving broader Western defender awareness.
- As of 2026-05-29, CVE-2026-22679 (Weaver E-cology dubboApi unauth RCE, CVSS 9.8) remains actively exploited; despite the 2026-03-12 patch removing the endpoint, in-the-wild abuse since mid-March is confirmed by Vega, Shadowserver, BleepingComputer and SC Media. A public PoC exists and the large unpatched China-centric install base keeps it a live n-day threat.
Sources cited for Weaver E-cology Unauthenticated RCE (CVE-2026-22679)
- BleepingComputer — Weaver E-cology critical bug exploited in attacks since March
- NVD — CVE-2026-22679
- VulnCheck Advisory — Weaver E-cology 10.0 Unauthenticated RCE via dubboApi Debug Endpoint
- Qi'anxin Threat Intelligence Center — CVE-2026-22679 Notice
- Weaver Official Security Patch Download Center
- Shadowserver Foundation — Active Exploitation Telemetry
- GitHub — keraattin/CVE-2026-22679 (Detection Tooling)
- CWE-306 — Missing Authentication for Critical Function
- CWE-94 — Improper Control of Generation of Code
- Apache Dubbo RPC Framework Documentation
Detection coverage for TL-2026-0455
As of 2026-05-04, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0455 across Splunk SPL, Microsoft KQL and Sigma, covering 18 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.