CVE-2026-24916 PUBLISHED

Assigner: huawei
Reserved: 28.01.2026 Published: 06.02.2026 Updated: 06.02.2026

Identity authentication bypass vulnerability in the window module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Metrics

CVSS Vector: CVSS:3.1/AV:P/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
CVSS Score: 5.9

Product Status

Vendor Huawei
Product HarmonyOS
Versions Default: unaffected
  • Version 6.0.0 is affected

References

Problem Types

  • CWE-200 Exposure of Sensitive Information to an Unauthorized Actor CWE