CVE-2026-41971
published 2026-05-15CVE-2026-41971: Permission control vulnerability in the security control module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
PriorityP424medium5.5CVSS 3.1
AVLACLPRNUIRSUCHINAN
EPSS
0.08%
0.3th percentile
Permission control vulnerability in the security control module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| huawei | harmonyos | — | — |
| huawei | harmonyos | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-qh29-mq6c-xg5v: Permission control vulnerability in the security control module
ghsa_unreviewed·2026-05-15
CVE-2026-41971 [MEDIUM] GHSA-qh29-mq6c-xg5v: Permission control vulnerability in the security control module
Permission control vulnerability in the security control module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
VulDB
Huawei HarmonyOS 5.1.0/6.0.0 Security Control logic error
vuldb·2026-05-15·CVSS 5.5
CVE-2026-41971 [MEDIUM] Huawei HarmonyOS 5.1.0/6.0.0 Security Control logic error
A vulnerability was found in Huawei HarmonyOS 5.1.0/6.0.0 and classified as problematic. The affected element is an unknown function of the component Security Control Module. Such manipulation leads to business logic errors.
This vulnerability is uniquely identified as CVE-2026-41971. Local access is required to approach this attack. No exploit exists.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-05-15
Published