Cyber Resilience

CVE-2026-24923

Huawei Harmonyos 6.0.0

Published
06 February 2026
Modified
10 February 2026
Patch / advisory
CVSS Score v3.1 6.3
Click a component to see what it means
Raw vectorCVSS:3.1/AV:A/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H
EPSS Score 0.0011 2th percentile
Risk Priority 44 floored blend · peak EPSS

Summary

CVE-2026-24923 is a medium-severity an unspecified weakness vulnerability in Huawei Harmonyos. Its CVSS base score is 6.3 (Medium).

Operationally, ranked at the 2th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog.

The strongest mitigations our analysis identified map to AC-3 (Access Enforcement) and AC-6 (Least Privilege) — see the control section below for these in your framework.

EU & UK References

Vulnerability Data

Permission control vulnerability in the HDC module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

CWE(s)

Related Threats

MITRE ATT&CK Enterprise TechniquesAI

Insufficient information to map techniques.
Confidence: LOW · MITRE ATT&CK Enterprise v19.0

CVEs Like This One

CVE-2025-68967Same product: Huawei Harmonyos
CVE-2024-54103Same product: Huawei Harmonyos
CVE-2025-48903Same product: Huawei Harmonyos
CVE-2023-52106Same product: Huawei Harmonyos
CVE-2023-52721Same product: Huawei Harmonyos
CVE-2026-24931Same product: Huawei Harmonyos
CVE-2026-24924Same product: Huawei Harmonyos
CVE-2024-51524Same product: Huawei Harmonyos
CVE-2024-54104Same product: Huawei Harmonyos
CVE-2025-66319Same product: Huawei Harmonyos

Affected Assets

huawei
harmonyos
6.0.0

Mitigating Controls

Control response

Prevent
Stop it (NIST 800-53)
  • AC-3 Access Enforcement
  • AC-6 Least Privilege
  • AC-4 Information Flow Enforcement
Detect
Catch it (NIST detect / respond)

Harden
Shrink the surface (DISA STIG)

Validate
Prove the fix (OWASP ASVS)

Mitigating Controls (NIST 800-53 r5) AI

prevent

Directly enforces access control policies on the HDC module to block unauthorized permission usage that leads to confidentiality loss.

prevent

Limits privileges assigned to the HDC module so that a permission flaw cannot be exploited to access confidential services.

prevent

Enforces information flow rules that would restrict data exposure resulting from the CWE-264 permission flaw.

References