Weaver (Fanwei) E-cology deployments are affected by two high-severity vulnerabilities that allow unauthenticated attackers to compromise exposed servers. CVE-2026-22679 impacts E-cology 10.0 versions prior to 20260312 and enables remote code execution through the /papi/esearch/data/devops/dubboApi/debug/method endpoint, where attacker-controlled interfaceName and methodName POST parameters can abuse exposed debug functionality to run arbitrary commands. The issue is classified as CWE-306 and carries high impact across confidentiality, integrity, and availability, with exploitation observed in the wild by the Shadowserver Foundation.
A second flaw, CVE-2022-50992, affects E-cology 9.5 versions prior to 10.52 and allows unauthenticated arbitrary file reads through the XmlRpcServlet XML-RPC interface. Attackers can supply file paths to the WorkflowService.getAttachment and WorkflowService.LoadTemplateProp methods to retrieve sensitive files from the server, including configuration data and database credentials. The vulnerability is mapped to CWE-22, and Shadowserver reported exploitation evidence dating back to 2022, underscoring continued exposure risk for internet-facing E-cology systems that remain unpatched.

See which actors are running it and whether you're in range.
7 events from the most recent confirmed update back to the earliest known activity.
VulnCheck's disclosure channel newly received CVE-2022-50992 on April 30, 2026. The vulnerability affects Weaver E-cology 9.5 versions prior to 10.52.
A GitHub repository published technical analysis for CVE-2026-22679, including proof-of-concept details for unauthenticated RCE via the exposed debug endpoint, plus indicators of compromise and detection guidance. The material also outlined mitigation steps such as blocking the endpoint, restricting exposure, and reviewing logs and hosts for compromise.
VulnCheck's disclosure channel newly received CVE-2026-22679 on April 7, 2026. The vulnerability affects Weaver E-cology 10.0 versions prior to 20260312.
The Shadowserver Foundation first observed exploitation of CVE-2026-22679, an unauthenticated remote code execution vulnerability in Weaver E-cology 10.0's /papi/esearch/data/devops/dubboApi/debug/method endpoint. The issue can be abused through attacker-controlled interfaceName and methodName parameters to execute arbitrary commands.
Vega Research Team reported evidence that CVE-2026-22679 was being exploited as early as March 17, 2026, shortly after Weaver released build 20260312. The activity involved multi-stage intrusion attempts following unauthenticated RCE via the exposed debug API endpoint.
Weaver released build 20260312 for E-cology 10.0 in mid-March 2026, removing the exposed debug API endpoint that enabled unauthenticated remote code execution via CVE-2026-22679. The report says attackers began exploiting the flaw shortly after this fix was released and before public disclosure.
The Shadowserver Foundation first observed exploitation of CVE-2022-50992, an unauthenticated arbitrary file read vulnerability in Weaver E-cology 9.5's XmlRpcServlet XML-RPC endpoint. The flaw allows remote attackers to read arbitrary files, including sensitive configuration files and database credentials.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 14 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
10 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcescworld.com
Open sourcecybersecuritynews.com
Open sourcethehackernews.com
Open sourcecvefeed.io
Open sourceblog.vega.io
Open sourcegithub.com
Open sourcecvefeed.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.