Weaver E-cology Unauthenticated RCE Debug API | MSSP Advisory

Critical
DateMay 5, 2026
📋Executive Summary
Weaver E-cology enterprise automation platform contains a critical unauthenticated remote code execution vulnerability (CVE-2026-22679) with a CVSS score of 9.8. Attackers exploit the /papi/esearch/data/devops debug API endpoint to execute arbitrary commands without authentication on versions prior to 20260312. The flaw is under active exploitation in the wild.
⚠️Why It Matters for MSSPs
If your RMM or PSA integrates with Weaver E-cology platforms for client workflow management, compromised instances provide direct access to your management infrastructure and all connected client networks. Your clients running this platform face immediate remote takeover risk, and failing to warn them about an actively exploited 9.8 CVSS flaw creates liability exposure when breaches occur.
Recommended Action
Audit all client environments for Weaver E-cology installations immediately and demand emergency patching to version 20260312 or newer within 24 hours.
🔒
Partner content — get access free
The recommended action is included in your white-labeled advisory — ready to send to clients under your name.
Get your first advisory free →
🏷️Threat Category
Zero-Day

Partner MSSPs receive the full advisory — talking points, actions, and social posts — under their own brand.