Description
Permission control vulnerability in the notification module. Impact: Successful exploitation of this vulnerability may affect availability.
Published: 2026-08-17
Score: 5.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a permission control flaw in the notification module of Huawei EMUI and HarmonyOS. It allows an attacker to bypass expected access restrictions, leading to a denial of service that impacts system availability. The weakness is classified as CWE-264, indicating improper privilege management.

Affected Systems

The flaw impacts Huawei's EMUI operating system and HarmonyOS. No specific product versions are listed in the advisory, so all currently deployed firmware versions may be affected until a vendor fix is released.

Risk and Exploitability

The CVSS base score of 5.1 indicates a moderate severity. EPSS is unavailable and the vulnerability is not listed in the CISA KEV catalog, suggesting low to moderate promise of exploitation in the wild. The likely attack vector is local, as the notification module typically requires user or privileged access; however the description does not detail whether remote exploitation is possible. Operators should consider that a successful breach of the permission model can disrupt service availability on the device. Remediation depends on vendor updates, but in interim users can isolate notification services if the platform supports it.

Generated by OpenCVE AI on August 17, 2026 at 11:06 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply any Huawei EMUI or HarmonyOS patches or firmware updates that address the notification permission control flaw when they become available.
  • Review device configuration to restrict or disable unnecessary notification services that could expose the vulnerability until a patch is applied.
  • Verify device permissions and user roles to enforce the principle of least privilege, ensuring that only authorized accounts can access the notification module.

Generated by OpenCVE AI on August 17, 2026 at 11:06 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 28 Aug 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 17 Aug 2026 12:15:00 +0000

Type Values Removed Values Added
First Time appeared Huawei
Huawei emui
Huawei harmonyos
Vendors & Products Huawei
Huawei emui
Huawei harmonyos

Mon, 17 Aug 2026 11:30:00 +0000

Type Values Removed Values Added
Title Permission Control Issue in Huawei EMUI and HarmonyOS Notification Module Causing Availability Risk

Mon, 17 Aug 2026 09:00:00 +0000

Type Values Removed Values Added
Description Permission control vulnerability in the notification module. Impact: Successful exploitation of this vulnerability may affect availability.
Weaknesses CWE-264
References
Metrics cvssV3_1

{'score': 5.1, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: huawei

Published:

Updated: 2026-08-28T17:51:28.679Z

Reserved: 2026-05-29T03:16:14.062Z

Link: CVE-2026-49303

cve-icon Vulnrichment

Updated: 2026-08-28T17:51:23.799Z

cve-icon NVD

Status : Deferred

Published: 2026-08-17T09:17:30.270

Modified: 2026-08-28T20:17:37.313

Link: CVE-2026-49303

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-17T12:00:13Z

Weaknesses