# Weaver E-cology Unauthenticated RCE (CVE-2026-22679) — Active Exploitation Since Mid-March 2026 via dubboApi Debug Endpoint

> CVE-2026-22679 is a critical (CVSS 9.8) unauthenticated remote code execution flaw in Weaver (Fanwei) E-cology 10.0 builds prior to 20260312, caused by an exposed Dubbo RPC debug endpoint at /papi/esearch/data/devops/dubboApi/debug/method that accepts attacker-controlled interfaceName and methodName POST parameters and routes them to backend command-execution helpers without authentication or input validation. Vega researchers documented in-the-wild exploitation beginning approximately 2026-03-17 (~five days after the silent vendor patch on 2026-03-12 and roughly two weeks before public disclosure on 2026-03-31), with attackers using Goby-linked ICMP callbacks for capability checks, multiple PowerShell-based fileless payload downloads, an MSI installer named fanwei0324.msi, and reconnaissance commands (whoami, ipconfig, tasklist) parented by the Tomcat-bundled java.exe service process. Shadowserver Foundation independently confirmed scanning and exploitation starting 2026-03-31 UTC, and the issue affects organizations across Chinese government, financial services, large enterprise, and higher education sectors that depend on this widely deployed OA platform.

- **Published:** 2026-05-04T23:15:00Z
- **Last reviewed:** 2026-05-04T23:15:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-0455
- **ID:** TL-2026-0455
- **Severity:** CRITICAL (CVSS 9.8)
- **Category:** VULNERABILITY
- **Status:** ACTIVE
- **Detections:** 9 · **IOCs:** 18 (full data via the Threadlinqs MCP server — Purple tier)
- **CVEs:** CVE-2026-22679

## Description

## Overview

CVE-2026-22679 is an unauthenticated remote code execution vulnerability affecting Weaver E-cology 10.0 (all builds prior to 20260312). E-cology, developed by Shanghai Weaver Network Co. Ltd. (泛微 / Fanwei), is one of the most widely deployed enterprise office automation (OA) and collaboration platforms in mainland China, used across government agencies, state-owned enterprises, banks and insurance firms, large private corporations, and universities. The product bundles document management, workflow automation, HR, messaging, calendaring, and portal services on top of an embedded Tomcat/JBoss container running a Java application with the Apache Dubbo RPC framework underneath.

The vulnerability resides in a development/diagnostics endpoint that was inadvertently shipped to production: `/papi/esearch/data/devops/dubboApi/debug/method`. This endpoint accepts unauthenticated HTTP POST requests and parses two attacker-controlled string parameters — `interfaceName` (a fully-qualified Dubbo interface class) and `methodName` (the method to invoke on that interface) — alongside a `parameters` array. The handler then resolves the requested interface/method via the Dubbo RPC layer and invokes it with the supplied parameters. Because the dispatch logic enforces no authentication, no allow-list of safe interfaces or methods, no parameter type checking, and no input sanitization, an attacker can pivot the endpoint into arbitrary OS command execution by selecting a command-execution helper class exposed to the RPC registry. The resulting child process inherits the privileges of the Weaver service account, which on Windows installations is typically a SYSTEM-level service account and on Linux installations is frequently root or a high-privileged service user.

## Root Cause and Exploitation Mechanics

The vendor patch released on 2026-03-12 simply removes the entire `/papi/esearch/data/devops/dubboApi/debug/method` route — there is no allow-list refactor or authentication wrapper, indicating the endpoint had no production purpose. NVD primary CWE classification is CWE-306 (Missing Authentication for Critical Function); third-party analysis additionally maps the issue to CWE-94 (Improper Control of Generation of Code) because attacker input directly drives RPC method selection.

An exploitation request looks like:

```
POST /papi/esearch/data/devops/dubboApi/debug/method HTTP/1.1
Host: <target>
Content-Type: application/json

{"interfaceName": "com.weaver.rpc.<command-helper-class>",
 "methodName": "<exec-method>",
 "parameters": ["<command>", "<arg1>", "<arg2>"]}
```

Because the request is a single unauthenticated POST and the response surface is shaped like a routine API call, exploitation traffic blends easily into normal application logs unless defenders explicitly look for the path.

## Observed Campaign (Vega Threat Intelligence)

Vega documented at least one extended campaign lasting roughly a week per targeted organization with several distinct phases. Each campaign began approximately 2026-03-17, only five days after Weaver's silent patch — a tempo that strongly suggests patch-diff exploit development by a capable, organized actor that monitors the vendor's official patch portal (https://www.weaver.com.cn/cs/securityDownload.html).

Phase 1 — Capability Probe: attackers issued ICMP `ping` commands from the Java process to a Goby-linked callback infrastructure to confirm RCE primitive worked end-to-end. Goby is a Chinese-language vulnerability scanner heavily used by both red teams and threat actors operating in the Sinophone space.

Phase 2 — PowerShell Payload Download: attackers issued obfuscated and fileless PowerShell commands (e.g., `powershell.exe -nop -w hidden -enc <base64>` style) to fetch follow-on payloads from external infrastructure. These were repeatedly blocked by endpoint defenses on the targets Vega observed.

Phase 3 — MSI Installer Deployment: after PowerShell failures, attackers attempted to deliver a target-aware MSI installer named `fanwei0324.msi` (the file name encodes the Chinese transliteration of Weaver — "Fanwei" / 泛微 — plus the date 03-24, suggesting build-naming discipline by the operator). The MSI failed to execute properly on the observed targets and no follow-on persistence was established.

Phase 4 — Reversion to Fileless RCE: after MSI failures, attackers cycled back to the dubboApi endpoint and used obfuscated PowerShell to repeatedly fetch remote scripts directly into memory.

Throughout all phases, recon commands `whoami`, `ipconfig`, and `tasklist` were observed parented by `java.exe` (the bundled Tomcat process). Vega assesses that despite repeated successful RCE, the actor never established persistent C2 — the campaign reads as an opportunistic mass-exploitation effort that reverted to recon-only when payload delivery failed, rather than a targeted intrusion with prepared tooling.

## Independent Confirmation

Shadowserver Foundation confirmed exploitation traffic against honeypots and customer telemetry beginning 2026-03-31 UTC, providing an independent floor on the active exploitation start date. VulnCheck published a formal advisory (VC-CVE-2026-22679) and the CVE was assigned by VulnCheck (disclosure@vulncheck.com) and published on NVD on 2026-04-07. BleepingComputer surfaced the campaign publicly on 2026-05-04.

## Affected Versions and Patch

E-cology 10.0 builds prior to 20260312 are vulnerable. The fixed build is 20260312, released 2026-03-12 as a security-only update available from https://www.weaver.com.cn/cs/securityDownload.html. The vendor advisory does not list workarounds — upgrading is the only recommended remediation. Older E-cology versions (9.x, 8.x, 7.x) have not been confirmed vulnerable but should be assessed against the vendor security portal which publishes per-line patches.

## Risk Profile

This vulnerability is high-impact because: (1) E-cology is internet-exposed at many Chinese organizations to support remote employee access; (2) the endpoint is unauthenticated with a deterministic, low-complexity exploit path; (3) the affected service typically runs with privileged service account credentials granting full host compromise on a single request; (4) public PoC scanners (Python, Nmap NSE) are now available, lowering the bar for opportunistic actors; (5) Weaver E-cology stores HR data, financial records, contracts, and signed approvals — making it both a high-value initial-access pivot and a high-value data target in its own right.

## MITRE ATT&CK

- T1595 Active Scanning
- T1595.002 Vulnerability Scanning
- T1583 Acquire Infrastructure
- T1608.001 Stage Capabilities: Upload Malware
- T1190 Exploit Public-Facing Application
- T1059.001 Command and Scripting Interpreter: PowerShell
- T1059.003 Command and Scripting Interpreter: Windows Command Shell
- T1569.002 System Services: Service Execution
- T1204 User Execution
- T1027 Obfuscated Files or Information
- T1027.010 Obfuscated Files or Information: Command Obfuscation
- T1620 Reflective Code Loading
- T1218.007 System Binary Proxy Execution: Msiexec
- T1033 System Owner/User Discovery
- T1016 System Network Configuration Discovery
- T1057 Process Discovery
- T1082 System Information Discovery
- T1071.001 Application Layer Protocol: Web Protocols
- T1105 Ingress Tool Transfer
- T1095 Non-Application Layer Protocol

## Sources

- [BleepingComputer — Weaver E-cology critical bug exploited in attacks since March](https://www.bleepingcomputer.com/news/security/weaver-e-cology-critical-bug-exploited-in-attacks-since-march/)
- [NVD — CVE-2026-22679](https://nvd.nist.gov/vuln/detail/CVE-2026-22679)
- [VulnCheck Advisory — Weaver E-cology 10.0 Unauthenticated RCE via dubboApi Debug Endpoint](https://www.vulncheck.com/advisories/weaver-e-cology-unauthenticated-rce-via-dubboapi-debug-endpoint)
- [Qi'anxin Threat Intelligence Center — CVE-2026-22679 Notice](https://ti.qianxin.com/vulnerability/notice-detail/1760)
- [Weaver Official Security Patch Download Center](https://www.weaver.com.cn/cs/securityDownload.html)
- [Shadowserver Foundation — Active Exploitation Telemetry](https://www.shadowserver.org/)
- [GitHub — keraattin/CVE-2026-22679 (Detection Tooling)](https://github.com/keraattin/CVE-2026-22679)
- [CWE-306 — Missing Authentication for Critical Function](https://cwe.mitre.org/data/definitions/306.html)
- [CWE-94 — Improper Control of Generation of Code](https://cwe.mitre.org/data/definitions/94.html)
- [Apache Dubbo RPC Framework Documentation](https://dubbo.apache.org/en/docs/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-0455
