Description
An issue in EcoOnline EHS (com.airsweb.v10) application for Android, version 0.2.499 allows a remote attacker to obtain sensitive information and execute arbitrary code via the AndroidManifest.xml component
Published: 2026-08-27
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An issue in EcoOnline EHS (com.airsweb.v10) for Android, version 0.2.499, allows a remote attacker to obtain sensitive information and execute arbitrary code by exploiting a flaw in the AndroidManifest.xml component. This vulnerability enables the attacker to run code with the application's privileges, potentially compromising device security and leaking confidential data. The impact is direct code execution and exposure of sensitive data within the mobile environment.

Affected Systems

Devices running the EcoOnline EHS application, Android version not specified but the flaw appears in the app package com.airsweb.v10 version 0.2.499. The vulnerability is specific to this application and affects all users who install or run this version.

Risk and Exploitability

The CVE admits remote code execution, which is a high‑severity risk. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, but the lack of neutralization steps combined with the ability to execute arbitrary code suggests a significant threat. The likely attack path involves a remote attacker manipulating or replacing the AndroidManifest.xml component to obtain elevated privileges. The risk remains elevated until a vendor patch or remediation is applied.

Generated by OpenCVE AI on August 27, 2026 at 17:26 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update to the latest verified version of the EcoOnline EHS application that resolves the manifest issue.
  • Examine the app’s AndroidManifest.xml to ensure no unintended exported components or excessive permissions are declared; remove or restrict them.
  • If the vulnerability cannot be fixed immediately, uninstall the affected application or avoid installing it until a patch is available.

Generated by OpenCVE AI on August 27, 2026 at 17:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 27 Aug 2026 17:45:00 +0000

Type Values Removed Values Added
Title Android Manifest Component Leading to Arbitrary Code Execution and Sensitive Data Exposure in EcoOnline EHS 0.2.499
Weaknesses CWE-200
CWE-94

Thu, 27 Aug 2026 16:45:00 +0000

Type Values Removed Values Added
Description An issue in EcoOnline EHS (com.airsweb.v10) application for Android, version 0.2.499 allows a remote attacker to obtain sensitive information and execute arbitrary code via the AndroidManifest.xml component
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-08-27T14:10:00.620Z

Reserved: 2026-02-16T00:00:00.000Z

Link: CVE-2026-26897

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-27T17:17:48.510

Modified: 2026-08-27T17:17:48.510

Link: CVE-2026-26897

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-27T17:30:12Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor

  • CWE-94

    Improper Control of Generation of Code ('Code Injection')