OVERVIEW CVE-2026-22679 is an unauthenticated remote code execution vulnerability affecting Weaver E-ecology versions 10.0 prior to build 20260312. The flaw exists in the /papi/esearch/data/devops/dubboApi/debug/method endpoint, where exposed debug functionality can be exploited by crafting POST requests with malicious interfaceName and methodName parameters to invoke command-execution helpers. SEVERITY This vulnerability carries a CVSS 3.1 score of 9.8 (CRITICAL) with a network-based attack vector requiring no authentication, no user interaction, and no special privileges. Successful exploitation grants complete system compromise with high impact to confidentiality, integrity, and availability. The attack requires only standard network access and minimal technical complexity, making it trivially exploitable. EXPLOITATION STATUS The vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog and shows low EPSS probability (0.0015) relative to other CVEs. However, exploitation evidence was first observed in the wild by Shadowserver Foundation on March 31, 2026. Organizations running unpatched E-ecology 10.0 instances should prioritize immediate patching to version 20260312 or later, as the vulnerability's critical severity combined with confirmed real-world observation presents significant risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 20260312CPE matchmatch criteria | cpe:2.3:a:weaver:e-cology:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.