Description
Permission control vulnerability in the Gallery module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
Published: 2026-08-17
Score: 6.2 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability is a permission control flaw in the Gallery module that can allow an attacker to access confidential information. The weakness permits disclosure of private media or related data, thereby impacting the confidentiality of user content.

Affected Systems

The flaw affects Huawei devices running EMUI and HarmonyOS, specifically the Gallery module. No precise version numbers are supplied, so all versions of these operating systems that include the Gallery application may be susceptible.

Risk and Exploitability

The CVSS score of 6.2 indicates moderate severity. EPSS data is not available, and the flaw is not listed in the CISA KEV catalog. Based on the description, it is inferred that exploitation requires an attacker to leverage improper permission checks within the Gallery app, most likely through local user interaction or compromised application privileges. The risk is therefore moderate and the attack vector is most plausibly local or requires the attacker to gain elevated access to the device.

Generated by OpenCVE AI on August 17, 2026 at 11:07 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Huawei security patch released in the August 2026 bulletin for EMUI and HarmonyOS Gallery
  • Revoke any unnecessary gallery permissions and enforce least privilege for the gallery app
  • Audit device permission settings regularly and ensure that only intended users have access to sensitive media

Generated by OpenCVE AI on August 17, 2026 at 11:07 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 17 Aug 2026 11:30:00 +0000

Type Values Removed Values Added
Title Permission Control Vulnerability in Huawei Gallery Module Allowing Unauthorized Information Disclosure
First Time appeared Huawei
Huawei emui
Huawei harmonyos
Vendors & Products Huawei
Huawei emui
Huawei harmonyos
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 17 Aug 2026 09:00:00 +0000

Type Values Removed Values Added
Description Permission control vulnerability in the Gallery module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
Weaknesses CWE-200
References
Metrics cvssV3_1

{'score': 6.2, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: huawei

Published:

Updated: 2026-08-17T10:46:04.022Z

Reserved: 2026-05-29T03:16:14.061Z

Link: CVE-2026-49301

cve-icon Vulnrichment

Updated: 2026-08-17T10:45:54.061Z

cve-icon NVD

Status : Deferred

Published: 2026-08-17T09:17:29.970

Modified: 2026-08-26T16:33:17.117

Link: CVE-2026-49301

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-17T11:15:04Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor