Description
Vulnerability of improper permission control in the print module.
Impact: Successful exploitation of this vulnerability may affect service confidentiality.
Published: 2026-02-06
Score: 6.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Confidentiality Disclosure
Action: Assess Impact
AI Analysis

Impact

The flaw arises from improper permission control within HarmonyOS’s print module. According to the description, an attacker who successfully exploits this weakness can access service‑related confidential information. The weakness is classified as CWE‑264, which denotes inappropriate privilege management. Because the vulnerability is present in the print component, a successful exploitation could expose private data that is normally protected from unauthorized users.

Affected Systems

Huawei HarmonyOS version 6.0.0 is affected, as indicated by the vendor/product list and CPE entry. All devices running this operating system version that still expose the print module are potentially vulnerable. The issue applies to the general HarmonyOS print service and does not seem isolated to a specific device or manufacturer model within the ecosystem.

Risk and Exploitability

The CVSS score of 6.1 reflects a moderate impact, while the EPSS score of less than 1 percent suggests that the exploitation probability is very low under current conditions. The vulnerability is not listed in the CISA KEV catalog, further supporting the notion that widespread attacks are unlikely. An attacker would need to locate and manipulate the print module’s permission configuration, which is typically only possible through local device access or by abusing a feature that exposes print capabilities over a network. No publicly disclosed exploits or proof‑of‑concept code are linked to this CVE, so the attack path remains theoretical at present.

Generated by OpenCVE AI on April 17, 2026 at 22:46 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply any official HarmonyOS update that addresses the print module permission issue, as indicated on Huawei’s support bulletin.
  • Limit print service access to authenticated and privileged users; remove or disable guest printing permissions on all affected devices.
  • If the print function is not required for normal operation, disable the print service or remove the related application package entirely.

Generated by OpenCVE AI on April 17, 2026 at 22:46 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 17 Apr 2026 23:15:00 +0000

Type Values Removed Values Added
Title Improper Permission Control in HarmonyOS Print Module

Thu, 05 Mar 2026 09:30:00 +0000

Type Values Removed Values Added
References

Thu, 05 Mar 2026 08:45:00 +0000

Type Values Removed Values Added
References

Mon, 09 Feb 2026 19:15:00 +0000

Type Values Removed Values Added
Weaknesses NVD-CWE-noinfo
CPEs cpe:2.3:o:huawei:harmonyos:6.0.0:*:*:*:*:*:*:*

Mon, 09 Feb 2026 11:00:00 +0000

Type Values Removed Values Added
First Time appeared Huawei
Huawei harmonyos
Vendors & Products Huawei
Huawei harmonyos

Fri, 06 Feb 2026 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 06 Feb 2026 09:30:00 +0000

Type Values Removed Values Added
Description Vulnerability of improper permission control in the print module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
Weaknesses CWE-264
References
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L'}


Subscriptions

Huawei Harmonyos
cve-icon MITRE

Status: PUBLISHED

Assigner: huawei

Published:

Updated: 2026-03-05T08:34:32.743Z

Reserved: 2026-01-28T06:05:05.257Z

Link: CVE-2026-24924

cve-icon Vulnrichment

Updated: 2026-02-06T16:09:09.191Z

cve-icon NVD

Status : Modified

Published: 2026-02-06T10:16:07.537

Modified: 2026-03-05T09:16:10.840

Link: CVE-2026-24924

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-17T23:00:12Z

Weaknesses