Description
Vulnerability of improper permission control in the theme setting module.
Impact: Successful exploitation of this vulnerability may affect service confidentiality.
Published: 2026-04-13
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Information Disclosure
Action: Update Software
AI Analysis

Impact

The vulnerability involves improper permission control within the theme setting component of Huawei's EMUI and HarmonyOS operating systems. By bypassing the intended access restrictions, an attacker could read or alter theme‑related configuration files, potentially revealing sensitive information tied to the service. The core weakness is a lack of proper privilege checks, aligning with CWE‑275. Consequently, the primary impact is a compromise of confidentiality, allowing disclosure of configuration details that may be used for further attacks.

Affected Systems

Manufacturers affected are Huawei, specifically software versions packaged under the EMUI and HarmonyOS product lines. No precise version numbers are supplied in the advisory; therefore, any device running these operating systems until further notice may be considered vulnerable. Users should consult Huawei’s consumer support bulletin for confirmation of affected releases.

Risk and Exploitability

The assigned CVSS score of 6.9 reflects a Moderate severity level, but the vulnerability is neither listed in CISA’s KEV catalog nor associated with a known exploit probability metric. Based on the description, it is inferred that the attack vector requires local interaction with the theme manager or exploitation of unprotected API endpoints exposed to the user interface. Because no remote exploitation mechanism is expressly documented, the exploitation likelihood may be moderate. Prompt patching remains the most effective countermeasure.

Generated by OpenCVE AI on April 13, 2026 at 05:20 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Visit the Huawei consumer support bulletin at https://consumer.huawei.com/en/support/bulletin/2026/4/ to review official patch information.
  • Download and install the latest firmware or OS update that addresses the permission control flaw.
  • After installing the update, verify the integrity of system configuration and confirm that theme settings cannot be accessed without appropriate privileges.

Generated by OpenCVE AI on April 13, 2026 at 05:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 14 Apr 2026 21:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:o:huawei:emui:14.0.0:*:*:*:*:*:*:*
cpe:2.3:o:huawei:emui:14.2.0:*:*:*:*:*:*:*
cpe:2.3:o:huawei:emui:15.0.0:*:*:*:*:*:*:*
cpe:2.3:o:huawei:harmonyos:4.0.0:*:*:*:*:*:*:*
cpe:2.3:o:huawei:harmonyos:4.2.0:*:*:*:*:*:*:*
cpe:2.3:o:huawei:harmonyos:4.3.0:*:*:*:*:*:*:*
cpe:2.3:o:huawei:harmonyos:4.3.1:*:*:*:*:*:*:*

Mon, 13 Apr 2026 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 13 Apr 2026 14:30:00 +0000

Type Values Removed Values Added
Title Improper Permission Control in Huawei EMUI and HarmonyOS Theme Setting Module

Mon, 13 Apr 2026 13:00:00 +0000

Type Values Removed Values Added
First Time appeared Huawei
Huawei emui
Huawei harmonyos
Vendors & Products Huawei
Huawei emui
Huawei harmonyos

Mon, 13 Apr 2026 04:00:00 +0000

Type Values Removed Values Added
Description Vulnerability of improper permission control in the theme setting module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
Weaknesses CWE-275
References
Metrics cvssV3_1

{'score': 6.9, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:C/C:H/I:L/A:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: huawei

Published:

Updated: 2026-04-13T15:02:31.882Z

Reserved: 2026-02-28T03:58:12.089Z

Link: CVE-2026-28553

cve-icon Vulnrichment

Updated: 2026-04-13T15:02:26.841Z

cve-icon NVD

Status : Analyzed

Published: 2026-04-13T04:16:03.650

Modified: 2026-04-14T21:16:18.783

Link: CVE-2026-28553

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-13T12:53:26Z

Weaknesses