Description
Permission control vulnerability in the multi-mode input module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
Published: 2026-08-17
Score: 6.2 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Huawei HarmonyOS contains a permission control flaw within its multi‑mode input module. An attacker who can circumvent the intended permission checks could read or capture sensitive service data. This vulnerability is tied to CWE‑200 and results in the loss of confidentiality for the affected services.

Affected Systems

The flaw is present in Huawei HarmonyOS. No specific version information is given in the advisory, so all released HarmonyOS builds remain at risk until a patch is deployed.

Risk and Exploitability

The CVSS score is 6.2, indicating a moderate severity level. EPSS information is not available and the issue is not listed in the CISA KEV catalog, so there is no current evidence of exploitation in the wild. The attack vector is not explicitly stated, but the multi‑mode input module suggests that local or semi‑local interaction may suffice to abuse the permission controls. Overall risk to confidentiality is moderate, requiring timely remediation.

Generated by OpenCVE AI on August 17, 2026 at 11:09 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest HarmonyOS update as published in the official Huawei advisory.
  • Re‑configure or temporarily disable the multi‑mode input module, ensuring that only trusted applications have the necessary permissions.
  • Audit permission assignments for all installed services, reducing privileges to the minimum required for operation.

Generated by OpenCVE AI on August 17, 2026 at 11:09 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 17 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 17 Aug 2026 11:30:00 +0000

Type Values Removed Values Added
Title Permission Control Vulnerability in HarmonyOS Multi‑Mode Input Module

Mon, 17 Aug 2026 09:45:00 +0000

Type Values Removed Values Added
First Time appeared Huawei
Huawei harmonyos
Vendors & Products Huawei
Huawei harmonyos

Mon, 17 Aug 2026 08:30:00 +0000

Type Values Removed Values Added
Description Permission control vulnerability in the multi-mode input module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
Weaknesses CWE-200
References
Metrics cvssV3_1

{'score': 6.2, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Huawei Harmonyos
cve-icon MITRE

Status: PUBLISHED

Assigner: huawei

Published:

Updated: 2026-08-17T15:17:37.664Z

Reserved: 2026-05-29T03:16:14.062Z

Link: CVE-2026-49307

cve-icon Vulnrichment

Updated: 2026-08-17T15:17:33.425Z

cve-icon NVD

Status : Deferred

Published: 2026-08-17T09:17:30.867

Modified: 2026-08-26T16:33:38.390

Link: CVE-2026-49307

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-17T11:15:04Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor