Description
Permission bypass vulnerability in the card module. Impact: Successful exploitation of this vulnerability may affect availability.
Published: 2026-07-15
Score: 6.6 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability is a permission bypass in the HarmonyOS card module. It permits an attacker to access card module functions that should be restricted, by circumventing the intended enforcement of least privilege. The direct result is a disruption of card module operations that can render related services unavailable, impacting the availability of the device’s core functionality.

Affected Systems

The affected product is Huawei HarmonyOS. Version information is not provided in the available data.

Risk and Exploitability

The CVSS score of 6.6 indicates a moderate severity. The EPSS score of less than 1% reflects a low probability that the flaw will be actively exploited, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, the attack vector is inferred to be an elevated privilege attempt, likely requiring local access to the device, as remote exploitation is not indicated. The exploit would involve manipulating permissions on the card module to cause a service disruption, resulting in availability impact.

Generated by OpenCVE AI on July 31, 2026 at 03:45 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update HarmonyOS to the latest firmware that contains the card module fix.
  • Consult the Huawei support bulletin linked in the references for detailed patch deployment steps.
  • Verify and enforce the correct permission settings for the card module to prevent unauthorized access
  • Monitor system logs and service availability after the update to ensure the card module operates normally

Generated by OpenCVE AI on July 31, 2026 at 03:45 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 31 Jul 2026 04:15:00 +0000

Type Values Removed Values Added
Title Permission Bypass in HarmonyOS Card Module Causing Availability Impact

Wed, 29 Jul 2026 03:15:00 +0000

Type Values Removed Values Added
Title Permission Bypass in HarmonyOS Card Module

Sat, 25 Jul 2026 07:45:00 +0000

Type Values Removed Values Added
Title Permission Bypass in HarmonyOS Card Module

Wed, 22 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Title Permission Bypass in Huawei HarmonyOS Card Module

Fri, 17 Jul 2026 05:45:00 +0000

Type Values Removed Values Added
Title Permission Bypass in Huawei HarmonyOS Card Module

Wed, 15 Jul 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Huawei
Huawei harmonyos
Vendors & Products Huawei
Huawei harmonyos

Wed, 15 Jul 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 15 Jul 2026 12:30:00 +0000

Type Values Removed Values Added
Description Permission bypass vulnerability in the card module. Impact: Successful exploitation of this vulnerability may affect availability.
Weaknesses CWE-264
References
Metrics cvssV3_1

{'score': 6.6, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H'}


Subscriptions

Huawei Harmonyos
cve-icon MITRE

Status: PUBLISHED

Assigner: huawei

Published:

Updated: 2026-07-15T13:07:59.827Z

Reserved: 2026-07-01T10:03:11.403Z

Link: CVE-2026-58555

cve-icon Vulnrichment

Updated: 2026-07-15T13:07:56.265Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T04:00:15Z

Weaknesses