Description
Permission control vulnerability in the notification service module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
Published: 2026-08-17
Score: 6.2 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A permission control flaw exists in HarmonyOS’s notification service module. The vulnerability allows an attacker to read data from the notification service that should be confidential, potentially exposing sensitive information related to the service’s operation. This weakness is classified as CWE‑200 and can lead to a compromise of service confidentiality.

Affected Systems

Huawei HarmonyOS devices are affected. No specific version numbers are provided, so all current releases should be considered at risk until a public patch is issued.

Risk and Exploitability

The CVSS score of 6.2 indicates a moderate level of severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, the attack vector is inferred to be local or through the delivery of crafted notifications, requiring interaction with the notification service. No information is available on remote exploitability or prerequisites beyond the presence of the vulnerable service.

Generated by OpenCVE AI on August 17, 2026 at 11:08 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the Huawei HarmonyOS update that contains the notification service patch as soon as it becomes available
  • Restrict notification permissions for third‑party apps until the patch is applied
  • Continuously monitor Huawei security bulletins for additional updates or workarounds

Generated by OpenCVE AI on August 17, 2026 at 11:08 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 17 Aug 2026 11:30:00 +0000

Type Values Removed Values Added
Title Permission Control Vulnerability in HarmonyOS Notification Service

Mon, 17 Aug 2026 09:45:00 +0000

Type Values Removed Values Added
First Time appeared Huawei
Huawei harmonyos
Vendors & Products Huawei
Huawei harmonyos

Mon, 17 Aug 2026 08:30:00 +0000

Type Values Removed Values Added
Description Permission control vulnerability in the notification service module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
Weaknesses CWE-200
References
Metrics cvssV3_1

{'score': 6.2, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Huawei Harmonyos
cve-icon MITRE

Status: PUBLISHED

Assigner: huawei

Published:

Updated: 2026-08-18T13:38:32.837Z

Reserved: 2026-05-29T03:16:14.061Z

Link: CVE-2026-49302

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-08-17T09:17:30.130

Modified: 2026-08-26T16:33:38.390

Link: CVE-2026-49302

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-17T11:15:04Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor