CVE-2026-26897

An issue in EcoOnline EHS (com.airsweb.v10) application for Android, version 0.2.499 allows a remote attacker to obtain sensitive information and execute arbitrary code via the AndroidManifest.xml component

  • Published Aug 27, 2026
  • CVSS 9.8 critical
  • 1.1% chance of exploitation in the next 30 days (EPSS)

CVE-2026-26897 at the National Vulnerability Database