CVE-2026-24924
Huawei Harmonyos 6.0.0
Raw vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:LSummary
CVE-2026-24924 is a medium-severity an unspecified weakness vulnerability in Huawei Harmonyos. Its CVSS base score is 6.1 (Medium).
Operationally, exploitation aligns with the MITRE ATT&CK technique Exploitation for Privilege Escalation (T1068); ranked at the 1th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog.
The strongest mitigations our analysis identified map to AC-3 (Access Enforcement) and AC-6 (Least Privilege) — see the control section below for these in your framework.
EU & UK References
- 🇪🇺 ENISA EUVD: EUVD-2026-5674
Vulnerability Data
Vulnerability of improper permission control in the print module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
- CWE(s)
Related Threats
MITRE ATT&CK Enterprise TechniquesAI
Why these techniques?
Improper permission control (CWE-264) in print module directly enables exploitation for privilege escalation to impact confidentiality.
CVEs Like This One
Affected Assets
Mitigating Controls
Control response
Mitigating Controls (NIST 800-53 r5) AI
Directly enforces access permissions on the print module to block unauthorized actions that could compromise confidentiality.
Limits privileges granted to the print module so that only the minimum required permissions are assigned, reducing the impact of the CWE-264 flaw.
Enforces information flow rules that can restrict print-module data paths and thereby protect confidentiality even when permission checks are flawed.