Junglewise Threat Intelligence

CVE-2026-26897: EcoOnline EHS information disclosure and code execution in AndroidManifest.xml

CVE-2026-26897 · Severity: critical · CVSS 9.8 · Published 2026-08-27

Executive brief

EcoOnline EHS is a mobile application for environmental, health, and safety (EHS) management on Android devices. A vulnerability in how the application handles its AndroidManifest.xml configuration allows a remote attacker to extract sensitive information and execute arbitrary code on affected devices, potentially compromising user data and device integrity.

Technical details

The vulnerability exists in the EcoOnline EHS Android application (version 0.2.499, package com.airsweb.v10) due to improper handling of the AndroidManifest.xml component. A remote attacker can exploit this vulnerability to obtain sensitive information and execute arbitrary code on the affected device. The vulnerability does not require user authentication or local access, making it remotely exploitable via a network vector. The exact attack mechanism appears to relate to manifest misconfigurations or exposed exported components that enable code execution and information disclosure.

Affected products

  • EcoOnline EHS 0.2.499

Timeline

  • 2026-08-27: disclosed

References