Junglewise Threat Intelligence

CVE-2026-49311: Huawei HarmonyOS permission control vulnerability in event notification module

CVE-2026-49311 · Severity: medium · CVSS 6.2 · Published 2026-09-09

Technologies: Huawei Emui, Huawei Harmonyos. Vendors: Huawei.

Executive brief

Huawei HarmonyOS contains a permission control flaw in its event notification system that allows unauthorized access or manipulation of notification events. Successful exploitation can disrupt system availability and prevent notifications from functioning correctly, affecting user experience and potentially impacting critical alerts on phones, tablets, and laptops.

Technical details

This is an improper permission control vulnerability (CWE-276) in HarmonyOS's event notification module. The flaw allows attackers to bypass permission checks governing event notification handling. The vulnerability is reachable via local attack vectors on affected devices. Successful exploitation may lead to denial of service or unauthorized access to notification streams. Patches are available through Huawei's September 2026 security updates for HarmonyOS 6.1.0 and related versions.

Affected products

  • Huawei HarmonyOS 6.1.0
  • Huawei EMUI 16.0.0, 15.0.0, 14.2.0, 14.0.0

Timeline

  • 2026-09-09: disclosed
  • 2026-09-05: advisory: Huawei security bulletin published

References

Related threats