Missing Authentication for Critical Function in E-cology - CVE-2026-22679
Published: May 5, 2026
E-cology
Weaver Network Co., Ltd.
Description
The vulnerability allows a remote attacker to compromise the affected system.
The vulnerability exists due to missing authorization checks at the "/papi/esearch/data/devops/dubboApi/debug/method" API endpoint. A remote non-authenticated attacker can send specially crafted HTTP POST requests to the affected endpoint and execute arbitrary commands on the system.