CVE-2026-26897

Critical severity, CVSS 9.8. EPSS: 1.1% chance of exploitation in the next 30 days.

An issue in EcoOnline EHS (com.airsweb.v10) application for Android, version 0.2.499 allows a remote attacker to obtain sensitive information and execute arbitrary code via the AndroidManifest.xml component

Published 2026-08-27. Last modified 2026-09-01.