CVE-2026-24923
Huawei Harmonyos 6.0.0
Raw vector
CVSS:3.1/AV:A/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:HSummary
CVE-2026-24923 is a medium-severity an unspecified weakness vulnerability in Huawei Harmonyos. Its CVSS base score is 6.3 (Medium).
Operationally, ranked at the 2th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog.
The strongest mitigations our analysis identified map to AC-3 (Access Enforcement) and AC-6 (Least Privilege) — see the control section below for these in your framework.
EU & UK References
- 🇪🇺 ENISA EUVD: EUVD-2026-5666
Vulnerability Data
Permission control vulnerability in the HDC module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
- CWE(s)
Related Threats
MITRE ATT&CK Enterprise TechniquesAI
Insufficient information to map techniques.CVEs Like This One
Affected Assets
Mitigating Controls
Control response
Mitigating Controls (NIST 800-53 r5) AI
Directly enforces access control policies on the HDC module to block unauthorized permission usage that leads to confidentiality loss.
Limits privileges assigned to the HDC module so that a permission flaw cannot be exploited to access confidential services.
Enforces information flow rules that would restrict data exposure resulting from the CWE-264 permission flaw.