thehackernews.com 5/5/2026, 8:11:42 AM · via preferred

CVE-2026-22679 hits Weaver E‑cology via debug API, enabling RCE

MetInfo, Weaver E-cology Vulnerabilities in Attackers’ Crosshairs

Two critical-severity flaws are being exploited in MetInfo and Weaver E-cology to execute arbitrary code remotely without authentication. In MetInfo, tracked as CVE-2026-29014 with a CVSS of 9.8, the issue arises from an unauthenticated PHP code injection path that accepts user input and allows remote code execution. On Weaver E-cology, CVE-2026-22679…

First seen 2026-05-05T08:11:42.703Z · Last seen 2026-05-05T10:02:05.161Z

CyberSIXT Evidence Panel
Primary Source weaver.com.cn
CVE Intel
CISA KEV Not in KEV
Patch Patch Available

WEAVER (Fanwei) E-cology contains a critical unauthenticated remote code execution flaw, CVE-2026-22679, affecting Weaver E-cology 10.0 versions prior to 20260312, and it is actively exploited via a debug API endpoint at /papi/esearch/data/devops/dubboApi/debug/method. Attackers can craft POST requests with attacker-controlled interfaceName and methodName parameters to reach command-execution helpers and achieve arbitrary command execution on the system, according to the NVD description.

Shadowserver Foundation observed the first signs of active exploitation on 31 March 2026, while QiAnXin reported reproducing the vulnerability in its alert on 17 March 2026; Vega Research Team later said it identified active exploitation dating back to 17 March 2026, five days after patches were shipped on 12 March 2026.

The campaign involved RCE verification, three failed payload drops, an attempted pivot to an MSI implant named fanwei0324[.]msi, and attempts to retrieve PowerShell payloads from attacker-controlled infrastructure, with discovery commands such as whoami, ipconfig and tasklist observed. A Python-based detection script by Kerem Oruc was released to help identify vulnerable Weaver E-cology instances, and users are advised to apply the updates to stay protected.

View Primary Source Via thehackernews.com

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline