Junglewise Threat Intelligence

CVE-2026-28751: OpenHarmony denial of service via improper input validation

CVE-2026-28751 · Severity: low · CVSS 3.3 · Published 2026-05-19

Technologies: OpenHarmony. Vendors: OpenHarmony.

Executive brief

A vulnerability in the OpenHarmony operating system allows a local user to cause a denial-of-service condition. This could result in system instability or the crashing of specific services, temporarily disrupting the device's availability for the user. Because the attack requires local access, it is primarily a risk on shared devices or from malicious applications already installed on the system.

Technical details

A denial-of-service (DoS) vulnerability exists in OpenHarmony v6.0 and earlier versions due to improper input validation (CWE-20). A local attacker with low privileges can exploit this flaw to trigger a service crash or system instability. The attack does not require user interaction and has no impact on data confidentiality or integrity. The vulnerability was disclosed by the OpenHarmony security team in their April 2026 security bulletin. Users are advised to monitor for official patches or updates to the OpenHarmony OS.

Affected products

  • OpenHarmony OpenHarmony v6.0 and prior versions

Timeline

  • 2026-05-19: disclosed: Initial NVD publication date

References

Related threats