Description
in OpenHarmony v6.0 and prior versions allow a local attacker cause information leak
Published: 2026-05-19
Score: 5.5 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The filemanagement_storage_service in OpenHarmony incorrectly preserves file permissions, allowing a local attacker to read data that should have been protected. This flaw is associated with CWE-281 and results in the leakage of sensitive information stored on the device.

Affected Systems

OpenHarmony OpenHarmony v6.0 and all earlier releases are affected.

Risk and Exploitability

The vulnerability has a CVSS score of 5.5, indicating moderate severity. The EPSS score is not available, and the flaw is not listed in the CISA KEV catalog. The attack vector is local; no remote exploitation is described. Because only users with local access can trigger the information leak, the risk is confined to compromised or compromised locally isolated environments.

Generated by OpenCVE AI on May 19, 2026 at 04:21 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Identify all devices running OpenHarmony v6.0 or earlier
  • Upgrade to a release that corrects the permission preservation flaw, or apply the vendor‑supplied patch when available
  • Configure the file management service to enforce least‑privilege access, restricting file operations to authorized users only

Generated by OpenCVE AI on May 19, 2026 at 04:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 19 May 2026 05:15:00 +0000

Type Values Removed Values Added
First Time appeared Openharmony
Openharmony openharmony
Vendors & Products Openharmony
Openharmony openharmony

Tue, 19 May 2026 03:30:00 +0000

Type Values Removed Values Added
Description in OpenHarmony v6.0 and prior versions allow a local attacker cause information leak
Title filemanagement_storage_service has an improper preservation of permissions vulnerability
Weaknesses CWE-281
References
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Openharmony Openharmony
cve-icon MITRE

Status: PUBLISHED

Assigner: OpenHarmony

Published:

Updated: 2026-05-19T03:08:35.465Z

Reserved: 2026-03-03T06:43:20.288Z

Link: CVE-2026-25850

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-05-19T04:16:28.423

Modified: 2026-05-19T04:16:28.423

Link: CVE-2026-25850

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-19T05:00:10Z

Weaknesses