Description
Permission control vulnerability in the device key management module. Impact: Successful exploitation of this vulnerability may affect availability.
Published: 2026-08-17
Score: 6.2 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A permission control weakness exists within the device key management module, which can allow an attacker to exploit inadequate access checks. The flaw is classified as CWE‑264, indicating insufficient authorization safeguards that could lead to improper use of cryptographic keys. If successfully exploited, the vulnerability may compromise the system’s ability to manage keys, potentially resulting in service disruption or denial of key-based authentication. No additional impact to confidentiality or integrity is described in the text.

Affected Systems

Huawei HarmonyOS devices are affected, though specific firmware or OS versions are not enumerated in the advisory. The vulnerability is tied to the key management component of the operating system and applies to all HarmonyOS platforms that include this module.

Risk and Exploitability

The CVSS score of 6.2 indicates a moderate severity level, with availability as the primary impact. An EPSS score is not provided, and the vulnerability is not listed in the CISA KEV catalog, suggesting that widespread exploitation is currently unlikely. The attack vector is not explicitly defined in the advisory; however, based on the nature of permission control flaws in key management, it is inferred that the attack would require either local access or a privilege elevation to manipulate or bypass permission checks. The lack of a publicly disclosed exploit further reduces the immediacy of risk, but the potential for service disruption warrants monitoring and remediation as soon as possible.

Generated by OpenCVE AI on August 17, 2026 at 11:08 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Check Huawei’s consumer support bulletin for any firmware or OS updates that address the key‑management permission issue
  • Apply any available patch, firmware, or security update for HarmonyOS as recommended by Huawei
  • Audit and tighten permission assignments for key‑management functions to enforce least privilege
  • Implement logging and monitoring of key‑management activity to detect anomalous behavior or unauthorized access attempts

Generated by OpenCVE AI on August 17, 2026 at 11:08 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 17 Aug 2026 12:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 17 Aug 2026 09:45:00 +0000

Type Values Removed Values Added
First Time appeared Huawei
Huawei harmonyos
Vendors & Products Huawei
Huawei harmonyos

Mon, 17 Aug 2026 08:45:00 +0000

Type Values Removed Values Added
Description Permission control vulnerability in the device key management module. Impact: Successful exploitation of this vulnerability may affect availability.
Weaknesses CWE-264
References
Metrics cvssV3_1

{'score': 6.2, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

Huawei Harmonyos
cve-icon MITRE

Status: PUBLISHED

Assigner: huawei

Published:

Updated: 2026-08-17T11:31:25.314Z

Reserved: 2026-05-29T03:16:14.062Z

Link: CVE-2026-49304

cve-icon Vulnrichment

Updated: 2026-08-17T11:31:21.197Z

cve-icon NVD

Status : Deferred

Published: 2026-08-17T09:17:30.433

Modified: 2026-08-26T16:33:17.117

Link: CVE-2026-49304

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-17T11:15:04Z

Weaknesses