Description
DoS vulnerability in the preview service module.
Impact: Successful exploitation of this vulnerability may affect availability.
Published: 2026-09-09
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Apply Patch
AI Analysis

Impact

A flaw has been found in the preview service module of Huawei HarmonyOS that allows an attacker to cause a denial of service. The vulnerability is a weakness in access control (CWE‑264) and can lead to a loss of availability if an attacker can trigger the service to consume excessive resources or crash. No information is provided about data disclosure or integrity impact. The attack would compromise the normal operation of the device by making the preview feature unusable or unstable.

Affected Systems

The affected product is Huawei HarmonyOS. Specific affected versions are not listed in the advisory, so all releases that include the preview service module may need to be evaluated. The advisory does not specify which versions or builds are impacted.

Risk and Exploitability

The CVSS score of 4.3 indicates a medium severity, while the EPSS score is not available, so the exploitation probability is unknown. The vulnerability is not listed in the CISA KEV catalog. The preview service module is likely exposed at the application level, which suggests that the possible attack vector could be remote over the network or local if the device is compromised. Based on the description, the attacker would need to send a specially crafted request to the preview service to trigger a resource exhaustion or crash, leading to denial of service.

Generated by OpenCVE AI on September 9, 2026 at 11:47 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply any vendor‑supplied patches or updates that address the preview service module once they become available.
  • If a patch is not yet available, restrict or disable the preview service on devices that do not require it, or limit access to trusted users only.
  • Implement basic rate limiting or resource monitoring for the preview service to detect and mitigate abnormal resource usage that could indicate exploitation.

Generated by OpenCVE AI on September 9, 2026 at 11:47 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 10 Sep 2026 14:00:00 +0000

Type Values Removed Values Added
First Time appeared Huawei
Huawei harmonyos
Vendors & Products Huawei
Huawei harmonyos

Thu, 10 Sep 2026 10:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 09 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
Title Denial of Service in HarmonyOS Preview Service Module

Wed, 09 Sep 2026 03:30:00 +0000

Type Values Removed Values Added
Description DoS vulnerability in the preview service module. Impact: Successful exploitation of this vulnerability may affect availability.
Weaknesses CWE-264
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L'}


Subscriptions

Huawei Harmonyos
cve-icon MITRE

Status: PUBLISHED

Assigner: huawei

Published:

Updated: 2026-09-09T20:51:33.765Z

Reserved: 2026-08-27T09:26:59.599Z

Link: CVE-2026-81644

cve-icon Vulnrichment

Updated: 2026-09-09T20:46:13.258Z

cve-icon NVD

Status : Deferred

Published: 2026-09-09T04:20:19.227

Modified: 2026-09-09T21:17:04.927

Link: CVE-2026-81644

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T13:45:16Z

Weaknesses