Permission Control Vulnerability in Huawei Window Module
CVE-2026-49312

4MEDIUM

Key Information:

Vendor

Huawei

Status
Vendor
CVE Published:
9 September 2026

What is CVE-2026-49312?

A permission control vulnerability has been identified in the window module of Huawei products. This flaw could potentially allow unauthorized access, leading to breaches in service confidentiality. Exploiting this vulnerability may give attackers the ability to manipulate sensitive data and access functionalities that should be restricted. Users and administrators are advised to assess their systems and implement appropriate measures to mitigate the risks associated with this vulnerability.

Affected Version(s)

HarmonyOS 6.1.0

References

CVSS V3.1

Score:
4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.