CVE-2026-24931
Huawei Harmonyos 5.1.0 … 6.0.0
Raw vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:LSummary
CVE-2026-24931 is a medium-severity an unspecified weakness vulnerability in Huawei Harmonyos. Its CVSS base score is 5.9 (Medium).
Operationally, ranked at the 1th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog.
The strongest mitigations our analysis identified map to AC-3 (Access Enforcement) and AC-6 (Least Privilege) — see the control section below for these in your framework.
EU & UK References
- 🇪🇺 ENISA EUVD: EUVD-2026-5670
Vulnerability Data
Vulnerability of improper criterion security check in the card module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
- CWE(s)
Related Threats
MITRE ATT&CK Enterprise TechniquesAI
Insufficient information to map techniques.CVEs Like This One
Affected Assets
Mitigating Controls
Control response
Mitigating Controls (NIST 800-53 r5) AI
Directly enforces access decisions so an improper criterion security check in the card module cannot be bypassed.
Limits privileges assigned to the card module, reducing the impact of any flawed permission check on service confidentiality.
Enforces information flow rules that would block unauthorized data paths resulting from the missing security criterion check.