Description
Permission control vulnerability in the file system. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
Published: 2026-07-15
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a permission control flaw in the file system that can allow an attacker to read or manipulate files that should be protected. It is categorized as CWE‑840, indicating that improperly configured permissions permit unauthorized access. If exploited, the flaw could compromise the confidentiality of the affected service by exposing sensitive data.

Affected Systems

The flaw affects Huawei products, specifically the EMUI interface and Harmony OS. No specific version numbers are provided, so all current releases remain potentially vulnerable until a vendor‑specified fix is released.

Risk and Exploitability

The CVSS score of 7.8 reflects a high severity level, but the EPSS score of less than 1% indicates a low likelihood of exploitation at present. The vulnerability is not listed in CISA’s KEV catalog. Based on the description, the most probable attack vector is via local or remote file system access that bypasses usual permission checks. Successful exploitation would primarily impact data confidentiality on the device or server.

Generated by OpenCVE AI on August 1, 2026 at 08:56 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest firmware or patch for EMUI or Harmony OS from Huawei’s official support site.
  • Restrict file system permissions to the minimum needed for all users and services, ensuring sensitive files are not readable by unauthorized accounts.
  • Enable and review system audit logs for file access anomalies and investigate any unauthorized access attempts.

Generated by OpenCVE AI on August 1, 2026 at 08:56 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 01 Aug 2026 09:15:00 +0000

Type Values Removed Values Added
Title File System Permission Control Vulnerability in Huawei EMUI and Harmony OS

Wed, 29 Jul 2026 03:15:00 +0000

Type Values Removed Values Added
Title Permission Control Vulnerability in Huawei EMUI and Harmony OS File System

Tue, 28 Jul 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Huawei
Huawei emui
Huawei harmonyos
Vendors & Products Huawei
Huawei emui
Huawei harmonyos

Sat, 25 Jul 2026 07:45:00 +0000

Type Values Removed Values Added
Title Permission Control Vulnerability in Huawei EMUI and Harmony OS File System

Wed, 22 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Title File System Permission Control Vulnerability Impacting Service Confidentiality

Fri, 17 Jul 2026 05:45:00 +0000

Type Values Removed Values Added
Title File System Permission Control Vulnerability Impacting Service Confidentiality

Wed, 15 Jul 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 15 Jul 2026 13:00:00 +0000

Type Values Removed Values Added
Description Permission control vulnerability in the file system. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
Weaknesses CWE-840
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: huawei

Published:

Updated: 2026-07-15T13:03:58.948Z

Reserved: 2026-07-01T10:03:11.403Z

Link: CVE-2026-58558

cve-icon Vulnrichment

Updated: 2026-07-15T13:03:51.790Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-01T09:00:04Z

Weaknesses