Threat reportVulnerabilityTL-2026-0455

Weaver E-cology Unauthenticated RCE (CVE-2026-22679) — Active Exploitation Since Mid-March 2026 via dubboApi Debug Endpoint

criticalACTIVE

Weaver E-cology Unauthenticated RCE (CVE-2026-22679) (TL-2026-0455), also tracked as Weaver E-cology dubboApi RCE, is a critical-severity software vulnerability scored CVSS 9.8, first published 2026-05-04. It has no confirmed attribution, affects Shanghai Weaver Network (Fanwei / 泛微) E-cology 10.0, references 1 CVE (CVE-2026-22679), maps to 20 MITRE ATT&CK techniques (T1016, T1027, T1027.010), and is covered by 9 detection rules and 18 indicators of compromise.

CVSS
9.8/10Critical
CVEs
1Referenced vulnerabilities
Techniques
20MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
18Indicators of compromise

Key facts for TL-2026-0455

Threat ID
TL-2026-0455
Also known as
Weaver E-cology dubboApi RCE, Fanwei E-cology Debug Endpoint RCE, E-cology 10.0 Unauthenticated RCE, VulnCheck VC-CVE-2026-22679
Severity
CRITICAL
CVSS
9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Status
ACTIVE
Category
VULNERABILITY
First published
Last reviewed
Attribution confidence
NONE
Motivation
UNKNOWN
Target sectors
government, financial, banking, insurance, education, higher-education, manufacturing, energy, telecommunications, state-owned-enterprise
Target regions
China, Hong Kong, Taiwan, Asia-Pacific
Detection rules
9
Indicators of compromise
18

Malware and tooling in Weaver E-cology Unauthenticated RCE (CVE-2026-22679)

Malware and tooling: Goby

How Weaver E-cology Unauthenticated RCE (CVE-2026-22679) works

CVE-2026-22679 is a critical (CVSS 9.8) unauthenticated remote code execution flaw in Weaver (Fanwei) E-cology 10.0 builds prior to 20260312, caused by an exposed Dubbo RPC debug endpoint at /papi/esearch/data/devops/dubboApi/debug/method that accepts attacker-controlled interfaceName and methodName POST parameters and routes them to backend command-execution helpers without authentication or input validation. Vega researchers documented in-the-wild exploitation beginning approximately 2026-03-17 (~five days after the silent vendor patch on 2026-03-12 and roughly two weeks before public disclosure on 2026-03-31), with attackers using Goby-linked ICMP callbacks for capability checks, multiple PowerShell-based fileless payload downloads, an MSI installer named fanwei0324.msi, and reconnaissance commands (whoami, ipconfig, tasklist) parented by the Tomcat-bundled java.exe service process. Shadowserver Foundation independently confirmed scanning and exploitation starting 2026-03-31 UTC, and the issue affects organizations across Chinese government, financial services, large enterprise, and higher education sectors that depend on this widely deployed OA platform.

## Overview

CVE-2026-22679 is an unauthenticated remote code execution vulnerability affecting Weaver E-cology 10.0 (all builds prior to 20260312). E-cology, developed by Shanghai Weaver Network Co. Ltd. (泛微 / Fanwei), is one of the most widely deployed enterprise office automation (OA) and collaboration platforms in mainland China, used across government agencies, state-owned enterprises, banks and insurance firms, large private corporations, and universities. The product bundles document management, workflow automation, HR, messaging, calendaring, and portal services on top of an embedded Tomcat/JBoss container running a Java application with the Apache Dubbo RPC framework underneath.

The vulnerability resides in a development/diagnostics endpoint that was inadvertently shipped to production: `/papi/esearch/data/devops/dubboApi/debug/method`. This endpoint accepts unauthenticated HTTP POST requests and parses two attacker-controlled string parameters — `interfaceName` (a fully-qualified Dubbo interface class) and `methodName` (the method to invoke on that interface) — alongside a `parameters` array. The handler then resolves the requested interface/method via the Dubbo RPC layer and invokes it with the supplied parameters. Because the dispatch logic enforces no authentication, no allow-list of safe interfaces or methods, no parameter type checking, and no input sanitization, an attacker can pivot the endpoint into arbitrary OS command execution by selecting a command-execution helper class exposed to the RPC registry. The resulting child process inherits the privileges of the Weaver service account, which on Windows installations is typically a SYSTEM-level service account and on Linux installations is frequently root or a high-privileged service user.

## Root Cause and Exploitation Mechanics

The vendor patch released on 2026-03-12 simply removes the entire `/papi/esearch/data/devops/dubboApi/debug/method` route — there is no allow-list refactor or authentication wrapper, indicating the endpoint had no production purpose. NVD primary CWE classification is CWE-306 (Missing Authentication for Critical Function); third-party analysis additionally maps the issue to CWE-94 (Improper Control of Generation of Code) because attacker input directly drives RPC method selection.

An exploitation request looks like:

``` POST /papi/esearch/data/devops/dubboApi/debug/method HTTP/1.1 Host: <target> Content-Type: application/json

{"interfaceName": "com.weaver.rpc.<command-helper-class>", "methodName": "<exec-method>", "parameters": ["<command>", "<arg1>", "<arg2>"]} ```

Because the request is a single unauthenticated POST and the response surface is shaped like a routine API call, exploitation traffic blends easily into normal application logs unless defenders explicitly look for the path.

## Observed Campaign (Vega Threat Intelligence)

Vega documented at least one extended campaign lasting roughly a week per targeted organization with several distinct phases. Each campaign began approximately 2026-03-17, only five days after Weaver's silent patch — a tempo that strongly suggests patch-diff exploit development by a capable, organized actor that monitors the vendor's official patch portal (https://www.weaver.com.cn/cs/securityDownload.html).

Phase 1 — Capability Probe: attackers issued ICMP `ping` commands from the Java process to a Goby-linked callback infrastructure to confirm RCE primitive worked end-to-end. Goby is a Chinese-language vulnerability scanner heavily used by both red teams and threat actors operating in the Sinophone space.

Phase 2 — PowerShell Payload Download: attackers issued obfuscated and fileless PowerShell commands (e.g., `powershell.exe -nop -w hidden -enc <base64>` style) to fetch follow-on payloads from external infrastructure. These were repeatedly blocked by endpoint defenses on the targets Vega observed.

Phase 3 — MSI Installer Deployment: after PowerShell failures, attackers attempted to deliver a target-aware MSI installer named `fanwei0324.msi` (the file name encodes the Chinese transliteration of Weaver — "Fanwei" / 泛微 — plus the date 03-24, suggesting build-naming discipline by the operator). The MSI failed to execute properly on the observed targets and no follow-on persistence was established.

Phase 4 — Reversion to Fileless RCE: after MSI failures, attackers cycled back to the dubboApi endpoint and used obfuscated PowerShell to repeatedly fetch remote scripts directly into memory.

Throughout all phases, recon commands `whoami`, `ipconfig`, and `tasklist` were observed parented by `java.exe` (the bundled Tomcat process). Vega assesses that despite repeated successful RCE, the actor never established persistent C2 — the campaign reads as an opportunistic mass-exploitation effort that reverted to recon-only when payload delivery failed, rather than a targeted intrusion with prepared tooling.

## Independent Confirmation

Shadowserver Foundation confirmed exploitation traffic against honeypots and customer telemetry beginning 2026-03-31 UTC, providing an independent floor on the active exploitation start date. VulnCheck published a formal advisory (VC-CVE-2026-22679) and the CVE was assigned by VulnCheck (disclosure@vulncheck.com) and published on NVD on 2026-04-07. BleepingComputer surfaced the campaign publicly on 2026-05-04.

## Affected Versions and Patch

E-cology 10.0 builds prior to 20260312 are vulnerable. The fixed build is 20260312, released 2026-03-12 as a security-only update available from https://www.weaver.com.cn/cs/securityDownload.html. The vendor advisory does not list workarounds — upgrading is the only recommended remediation. Older E-cology versions (9.x, 8.x, 7.x) have not been confirmed vulnerable but should be assessed against the vendor security portal which publishes per-line patches.

## Risk Profile

This vulnerability is high-impact because: (1) E-cology is internet-exposed at many Chinese organizations to support remote employee access; (2) the endpoint is unauthenticated with a deterministic, low-complexity exploit path; (3) the affected service typically runs with privileged service account credentials granting full host compromise on a single request; (4) public PoC scanners (Python, Nmap NSE) are now available, lowering the bar for opportunistic actors; (5) Weaver E-cology stores HR data, financial records, contracts, and signed approvals — making it both a high-value initial-access pivot and a high-value data target in its own right.

MITRE ATT&CK techniques used in TL-2026-0455

Discovery

T1016 System Network Configuration Discovery; T1033 System Owner/User Discovery; T1057 Process Discovery; T1082 System Information Discovery

Defense Evasion

T1027 Obfuscated Files or Information; T1027.010 Obfuscated Files or Information: Command Obfuscation; T1218.007 System Binary Proxy Execution: Msiexec; T1620 Reflective Code Loading

Execution

T1059.001 Command and Scripting Interpreter: PowerShell; T1059.003 Command and Scripting Interpreter: Windows Command Shell; T1204 User Execution; T1569.002 System Services: Service Execution

Command and Control

T1071.001 Application Layer Protocol: Web Protocols; T1095 Non-Application Layer Protocol; T1105 Ingress Tool Transfer

Initial Access

T1190 Exploit Public-Facing Application

Resource Development

T1583 Acquire Infrastructure; T1608.001 Stage Capabilities: Upload Malware

Reconnaissance

T1595 Active Scanning; T1595.002 Vulnerability Scanning

Affected products and versions in Weaver E-cology Unauthenticated RCE (CVE-2026-22679)

  • Shanghai Weaver Network (Fanwei / 泛微) — E-cology 10.0
    Vulnerable versions: all builds prior to 20260312
    Fixed in: 20260312; later monthly rollups
  • Shanghai Weaver Network (Fanwei / 泛微) — E-cology 9.0 / 8.0 / 7.0
    Vulnerable versions: status unconfirmed — consult Weaver security portal per-line advisories
    Fixed in: E9.0 build v10.79 (2025-09-25) and later

Remediation for Weaver E-cology Unauthenticated RCE (CVE-2026-22679)

Patches

  • Weaver E-cology 10.0 build 20260312 (released 2026-03-12) — security-only update available from official Weaver portal
  • Subsequent monthly security rollups — apply latest available build

Immediate actions

  • Block all HTTP/S requests to /papi/esearch/data/devops/dubboApi/debug/method at WAF, reverse proxy, or web server (nginx: location /papi/esearch/data/devops/dubboApi { return 403; })
  • Restrict E-cology administrative interfaces to internal networks only — remove direct internet exposure where possible and require VPN/bastion access
  • Hunt web access logs for POST requests to /papi/esearch/data/devops/dubboApi/debug/method since 2026-03-12; treat any hit as confirmed exploitation attempt
  • Hunt for child processes of Tomcat java.exe spawning powershell.exe, cmd.exe, whoami.exe, ipconfig.exe, tasklist.exe, or msiexec.exe with fanwei0324.msi argument
  • Block known indicator file name fanwei0324.msi via EDR file-write rules and AV signatures

Workarounds

  • WAF/reverse-proxy rule blocking the vulnerable URI path is an effective compensating control until patch can be applied
  • Disable internet exposure of E-cology entirely if patching cannot be scheduled within the next 24-48 hours

Longer-term hardening

  • Apply Weaver E-cology build 20260312 or later from https://www.weaver.com.cn/cs/securityDownload.html — the patch removes the vulnerable endpoint entirely
  • Deploy EDR with behavioral detection capable of flagging Java service-account spawning interactive shells or download utilities
  • Implement network segmentation around E-cology hosts so that even on RCE the Java service cannot pivot to AD domain controllers, file shares, or financial systems
  • Add WAF rules that alert on any access to URI paths containing /devops/dubboApi or /debug/method regardless of HTTP method
  • Establish a recurring vendor-patch monitoring process for Weaver security portal — patch within 72 hours of release given demonstrated patch-diff exploitation tempo
  • For organizations subject to Chinese MLPS / cybersecurity regulatory regimes, document this incident class in the annual cybersecurity self-assessment

CVEs associated with Weaver E-cology Unauthenticated RCE (CVE-2026-22679)

CVE-2026-22679

Weaknesses (CWE) in Weaver E-cology Unauthenticated RCE (CVE-2026-22679)

CWE-306, CWE-94, CWE-749

Timeline of Weaver E-cology Unauthenticated RCE (CVE-2026-22679)

  • Weaver releases E-cology 10.0 build 20260312 to its security download portal as a silent fix that fully removes the /papi/esearch/data/devops/dubboApi/debug/method route. No public CVE assignment or advisory accompanies the patch.
  • Vega Threat Intelligence observes the first in-the-wild exploitation, approximately five days after the silent vendor patch — a tempo consistent with patch-diff reverse engineering by an organized actor monitoring the Weaver security portal.
  • Attackers stage a target-aware MSI installer named fanwei0324.msi (Fanwei = Weaver romanized; 0324 = March 24), suggesting active build cadence on operator infrastructure.
  • Shadowserver Foundation independently records the first exploitation telemetry against honeypots and customer sensors at 2026-03-31 UTC, providing an authoritative floor on widespread scanning.
  • VulnCheck assigns and publishes CVE-2026-22679 with a formal advisory; NVD entry goes live with CVSS v3.1 9.8 / CVSS v4.0 9.3 and CWE-306 mapping.
  • Qi'anxin Threat Intelligence Center publishes a Chinese-language advisory (notice-detail/1760) covering CVE-2026-22679 for domestic defenders.
  • Detection-only Python scanner and Nmap NSE script released on GitHub (keraattin/CVE-2026-22679) — no exploitation primitive, but the endpoint signature is now public, lowering the bar for opportunistic actors.
  • NVD moves CVE-2026-22679 from 'Awaiting Analysis' to 'Analyzed', confirming CPE matches and CVSS metrics.
  • BleepingComputer publishes the Vega-sourced narrative covering the campaign timeline, payload chain (Goby → PowerShell → fanwei0324.msi), and reconnaissance commands — driving broader Western defender awareness.
  • As of 2026-05-29, CVE-2026-22679 (Weaver E-cology dubboApi unauth RCE, CVSS 9.8) remains actively exploited; despite the 2026-03-12 patch removing the endpoint, in-the-wild abuse since mid-March is confirmed by Vega, Shadowserver, BleepingComputer and SC Media. A public PoC exists and the large unpatched China-centric install base keeps it a live n-day threat.

Sources cited for Weaver E-cology Unauthenticated RCE (CVE-2026-22679)

Detection coverage for TL-2026-0455

As of 2026-05-04, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0455 across Splunk SPL, Microsoft KQL and Sigma, covering 18 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
18 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats