CRITICAL🇵🇱 Wersja polska

CVE-2026-28536

CVSS 9.6v3.1pub. 2026-03-05upd. 2026-03-06

Authentication bypass vulnerability in the device authentication module. Impact: Successful exploitation of this vulnerability will affect integrity and confidentiality.

🤖 AI Analysis
How it works

The vulnerability classified as CWE-305 (Authentication Bypass by Primary Weakness) results from a faulty implementation of the device authentication module in the HarmonyOS system. An attacker located on the same local network (vector AV:A) can bypass authentication mechanisms without possessing any privileges and without requiring user interaction. The attack scope extends beyond the targeted component (S:C), indicating the possibility of affecting other system resources.

Impact

Successful exploitation of the vulnerability leads to violations of data integrity and confidentiality in the system. An attacker can gain unauthorized access to protected resources and device functions by bypassing access control mechanisms.

Mitigation & patch

Apply patches available from the manufacturer according to the references — Huawei security bulletins from March 2026 available at: https://consumer.huawei.com/en/support/bulletin/2026/3/, https://consumer.huawei.com/en/support/bulletinlaptops/2026/3/, https://consumer.huawei.com/en/support/bulletinvision/2026/3/

Who is affected

Devices running Huawei HarmonyOS — specific versions indicated in the manufacturer's references (Huawei security bulletins from March 2026, covering consumer devices, laptops, and Vision series devices).

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
  • Huawei Harmonyos

    OS
    Huawei
    5.1.06.0.0
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Auth Bypass
CWE
References

Related vulnerabilities

CVE-2026-34865CRITICAL10.0PL ✓same product

HarmonyOS: przepełnienie bufora sterty (heap buffer overflow) w module WEB

CVE-2025-64314CRITICAL9.3PL ✓same product

Błąd kontroli uprawnień w module zarządzania pamięcią Huawei HarmonyOS

CVE-2024-42037CRITICAL9.3PL ✓same product

Nieobsłużony wyjątek w module Graphics systemów Huawei EMUI/HarmonyOS

CVE-2024-39671CRITICAL9.3PL ✓same product

Podatność kontroli dostępu w module weryfikacji bezpieczeństwa Huawei

CVE-2023-52538CRITICAL9.1PL ✓same product

Ominięcie weryfikacji nazwy pakietu w module HwIms (Huawei EMUI/HarmonyOS)