ZeroHour

CVE-2026-26897

niche

Remote Info Disclosure and Code Execution in EcoOnline EHS Android App 0.2.499

CVSS 3.1
9.8 critical
EPSS
<1%p52
Published
()
Modified
AI analysis

The EcoOnline EHS (com.airsweb.v10) Android application, version 0.2.499, contains a flaw rooted in its AndroidManifest.xml component that lets a remote attacker obtain sensitive information and execute arbitrary code. Because the issue is rated CVSS 9.8 with network access, low attack complexity, and no privileges or user interaction required, an attacker who can reach the affected component over the network can trigger it without tricking the user. Successful exploitation exposes sensitive data handled by the app and allows arbitrary code execution on the device running it. Affected users are employees and contractors running the EcoOnline EHS (Airsweb) Android app at the named version in enterprise EHS deployments. As of now there is no known public proof-of-concept, the flaw is not in CISA's KEV catalog, and EPSS estimates only a 0.7% probability of exploitation within 30 days.

What to do: Inventory managed Android devices (via MDM/EMM) for the package com.airsweb.v10 and confirm whether version 0.2.499 is installed; update the app through Google Play/your enterprise app channel as soon as EcoOnline publishes a patched release, since no fixed version is specified in the available data. Until patching, consider removing or restricting the app for users who handle sensitive data, and monitor for EcoOnline advisories or updates to this record.

Affected
EcoOnline EHS Android app (com.airsweb.v10)0.2.499 (the only version named; other affected versions not specified in available data)
Estimated exposure
nichelikely on the order of thousands of device installs among employees of EcoOnline/Airsweb enterprise customers (estimate; no public install counts available) — This is a niche enterprise EHS mobile app distributed primarily to employees of EcoOnline/Airsweb corporate customers rather than a consumer application, and no public download or scan data was available, so the estimate relies on typical…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

An issue in EcoOnline EHS (com.airsweb.v10) application for Android, version 0.2.499 allows a remote attacker to obtain sensitive information and execute arbitrary code via the AndroidManifest.xml component

Weakness
CWE-200
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.