Description
Permission control vulnerability in the event notification module.
Impact: Successful exploitation of this vulnerability may affect service confidentiality.
Published: 2026-09-09
Score: 8.6 High
EPSS: < 1% Very Low
KEV: No
Impact: Confidentiality compromise
Action: Apply patch
AI Analysis

Impact

The vulnerability is a permission control flaw in the event notification module of Huawei HarmonyOS. An attacker who successfully exploits it may gain unauthorized access to event data, allowing them to read confidential information that the system disseminates. This could lead to leakage of user data, system configuration, or communication events, thereby compromising the confidentiality of services running on the device.

Affected Systems

The flaw affects Huawei HarmonyOS across devices such as smartphones, laptops, vision devices, and wearables. The exact affected versions are not enumerated in the data, so any HarmonyOS build present during the September 2026 bulletin is potentially impacted.

Risk and Exploitability

The vulnerability carries a high CVSS score of 8.6 and is not listed in the CISA KEV catalog. The EPSS score is not available, indicating no publicly reported exploitation data. The likely attack vector is a local or remote exploitation through crafted event notifications, though the precise conditions are not detailed in the description. Given the high severity and lack of known mitigation, the risk to confidentiality remains significant.

Generated by OpenCVE AI on September 9, 2026 at 11:48 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the HarmonyOS security update available from Huawei’s September 2026 bulletin for the affected device type
  • Restrict event‑notification permissions to authorized services only, ensuring that untrusted processes cannot trigger or intercept notifications
  • Enable auditing and monitor event‑log activity for anomalous notifications or permission changes

Generated by OpenCVE AI on September 9, 2026 at 11:48 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 10 Sep 2026 15:00:00 +0000

Type Values Removed Values Added
First Time appeared Huawei
Huawei harmonyos
Vendors & Products Huawei
Huawei harmonyos

Wed, 09 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
Title Permission Control Vulnerability in HarmonyOS Event Notification Module

Wed, 09 Sep 2026 03:30:00 +0000

Type Values Removed Values Added
Description Permission control vulnerability in the event notification module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
Weaknesses CWE-264
References
Metrics cvssV3_1

{'score': 8.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H'}


Subscriptions

Huawei Harmonyos
cve-icon MITRE

Status: PUBLISHED

Assigner: huawei

Published:

Updated: 2026-09-09T20:51:34.042Z

Reserved: 2026-05-29T03:16:14.062Z

Link: CVE-2026-49310

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-09-09T04:17:58.680

Modified: 2026-09-09T21:17:02.313

Link: CVE-2026-49310

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T14:45:18Z

Weaknesses