CVE-2026-26897
Received Received - Intake

EcoOnline EHS Android App Information Disclosure and Code Execution

Vulnerability report for CVE-2026-26897, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-27

Last updated on: 2026-08-27

Assigner: MITRE

Description

An issue in EcoOnline EHS (com.airsweb.v10) application for Android, version 0.2.499 allows a remote attacker to obtain sensitive information and execute arbitrary code via the AndroidManifest.xml component

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-27
Last Modified
2026-08-27
Generated
2026-08-27
AI Q&A
2026-08-27
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
ecoonline ehs to 0.2.500 (exc)
ecoonline ehs 0.2.500

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a deep link validation bypass in the EcoOnline EHS Android app (version 0.2.499). It allows remote attackers to bypass domain checks and load malicious web content within the trusted app by exploiting improper handling of custom schemes like 'ehs-app://'. The app rewrites these schemes to 'https://' without validating the host, enabling phishing attacks via fake login pages.

Detection Guidance

Check if the installed version of EcoOnline EHS Android app is below 0.2.500. Inspect the app's deep link handling by reviewing AndroidManifest.xml for improper intent filters or missing domain validation. Monitor network traffic for suspicious ehs-app:// deep links redirecting to external domains.

Impact Analysis

An attacker could trick you into clicking a malicious link, causing the app to display a fake login page under their control. If you enter credentials, the attacker could steal them. The vulnerability also allows execution of arbitrary code within the app's context.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, violating GDPR (data protection) and HIPAA (health information privacy) requirements. Organizations using the app may face compliance breaches if user credentials or sensitive data are exposed due to the flaw.

Mitigation Strategies

Update the EcoOnline EHS Android app to version 0.2.500 or later immediately. Disable deep link handling for untrusted sources if possible. Educate users to avoid clicking suspicious links in emails or messages. Monitor for phishing attempts exploiting this flaw.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-26897. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart