Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-22679

52
FAUCET Score

OVERVIEW CVE-2026-22679 is an unauthenticated remote code execution vulnerability affecting Weaver E-ecology versions 10.0 prior to build 20260312. The flaw exists in the /papi/esearch/data/devops/dubboApi/debug/method endpoint, where exposed debug functionality can be exploited by crafting POST requests with malicious interfaceName and methodName parameters to invoke command-execution helpers. SEVERITY This vulnerability carries a CVSS 3.1 score of 9.8 (CRITICAL) with a network-based attack vector requiring no authentication, no user interaction, and no special privileges. Successful exploitation grants complete system compromise with high impact to confidentiality, integrity, and availability. The attack requires only standard network access and minimal technical complexity, making it trivially exploitable. EXPLOITATION STATUS The vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog and shows low EPSS probability (0.0015) relative to other CVEs. However, exploitation evidence was first observed in the wild by Shadowserver Foundation on March 31, 2026. Organizations running unpatched E-ecology 10.0 instances should prioritize immediate patching to version 20260312 or later, as the vulnerability's critical severity combined with confirmed real-world observation presents significant risk.

Impacted Technologies

VendorProductVersion(s)CPE
< 20260312CPE matchmatch criteria
cpe:2.3:a:weaver:e-cology:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 4.0

9.3CRITICAL

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Attack Vector
NETWORK
Attack Complexity
LOW
Attack Requirements
NONE
Privileges Required
NONE
User Interaction
NONE
VS Confidentiality
HIGH
VS Integrity
HIGH
VS Availability
HIGH
SS Confidentiality
NONE
SS Integrity
NONE
SS Availability
NONE
Exploit Maturity
NOT_DEFINED
CvssVersion
4.0

Exploit Intelligence

EPSS Score
21.48%
Probability of exploitation in next 30 days
EPSS Percentile
97.4%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.2148 is in the 94th percentile among its peer group of 36,835 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Remediation records are not available for this CVE.

References

blog.vega.io / posts/cve-2026-22679-weaver-ecology-exploitation
h4cker.zip / post/d5d211
Broken Link
ti.qianxin.com / vulnerability/notice-detail/1760
Third Party Advisory
vulncheck.com / advisories/weaver-e-cology-unauthenticated-rce-via-dubboapi-debug-endpoint
Third Party Advisory
weaver.com.cn / cs/securityDownload.html
Patch