Description
Permission control vulnerability in the app management module.
Impact: Successful exploitation of this vulnerability may affect availability.
Published: 2026-09-09
Score: 6.2 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Availability disruption due to improper permission handling
Action: Apply Patch
AI Analysis

Impact

A permission control vulnerability exists in the app management module of Huawei EMUI and HarmonyOS, allowing an attacker to influence the availability of device services. The flaw, identified as CWE‑264, indicates improper privilege management, which could potentially let a malicious actor perform unauthorized changes that disrupt normal operation.

Affected Systems

Affected systems include Huawei EMUI operating systems and Huawei HarmonyOS. No specific firmware or hardware versions are listed in the advisory.

Risk and Exploitability

The CVSS score of 6.2 classifies the risk as moderate. No EPSS score is available and the vulnerability is not listed in the CISA KEV catalog, suggesting no confirmed high‑profile exploits yet. The attack vector is inferred to be local or application‑level, requiring elevated or mis‑used permissions to affect availability. The overall risk remains moderate but warrants timely remediation.

Generated by OpenCVE AI on September 9, 2026 at 11:22 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the device firmware to the latest version released by Huawei in the September 2026 support bulletins.
  • Restrict app‑management permissions, ensuring only authorized accounts can modify or uninstall applications.
  • Monitor device logs for anomalous attempts to manipulate application settings and enforce least‑privilege access rules.

Generated by OpenCVE AI on September 9, 2026 at 11:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 10 Sep 2026 14:00:00 +0000

Type Values Removed Values Added
First Time appeared Huawei
Huawei emui
Huawei harmonyos
Vendors & Products Huawei
Huawei emui
Huawei harmonyos

Thu, 10 Sep 2026 10:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 09 Sep 2026 11:45:00 +0000

Type Values Removed Values Added
Title Permission Control Vulnerability in App Management Module

Wed, 09 Sep 2026 04:15:00 +0000

Type Values Removed Values Added
Description Permission control vulnerability in the app management module. Impact: Successful exploitation of this vulnerability may affect availability.
Weaknesses CWE-264
References
Metrics cvssV3_1

{'score': 6.2, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: huawei

Published:

Updated: 2026-09-09T20:51:33.218Z

Reserved: 2026-04-23T01:42:44.930Z

Link: CVE-2026-41987

cve-icon Vulnrichment

Updated: 2026-09-09T20:46:07.566Z

cve-icon NVD

Status : Deferred

Published: 2026-09-09T04:17:57.760

Modified: 2026-09-09T21:17:02.100

Link: CVE-2026-41987

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T13:45:16Z

Weaknesses