CVE-2026-28539

Medium
|5.5
No Exploit

Plain English Summary

AI-powered analysis for quick understanding

An attacker could exploit a weakness in the certificate management system of HarmonyOS to potentially access sensitive information, compromising the confidentiality of services. This vulnerability requires the attacker to have some level of access to the system to be effective.

Technical Description

Data processing vulnerability in the certificate management module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

CVSS Vector Analysis

Attack VectorLocal
Attack ComplexityLow
Privileges RequiredLow
User InteractionNone
Confidentiality ImpactHigh
Integrity ImpactNone
Availability ImpactNone
ScopeUnchanged

Vector String

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Exploit Resources

Search for proof-of-concept code and exploit modules

Official References

Est. Bounty
$759($500-$1K)
Vendor Response
Grade APatched in 0 days

Quick Information

Published

Mar 5, 2026

about 1 month ago

Last Modified

Mar 5, 2026

about 1 month ago

Vendor

huawei

Product

harmonyos

Related Vulnerabilities

CVE-2026-28551Medium

This vulnerability allows an attacker to disrupt the security management of Huawei devices running HarmonyOS, potentially causing the system to become unavailable. To exploit this issue, the attacker must be able to trigger a race condition, which occurs when two processes try to access the same resource at the same time.

CVE-2026-28549Medium

This vulnerability allows an attacker to disrupt the permission management system on HarmonyOS, potentially causing the service to become unavailable. To exploit this, the attacker needs to take advantage of a timing issue in how permissions are handled, which could lead to service interruptions.

CVE-2026-28548Medium

This vulnerability allows an attacker to potentially access sensitive information from the email application due to a failure in properly verifying user actions. To exploit this, the attacker would need to trick the application into accepting malicious inputs, which could compromise the confidentiality of user data.

CVE-2026-28547Medium

This vulnerability allows an attacker to potentially disrupt the operation of HarmonyOS by exploiting an issue with uninitialized pointers in the scanning module. Successful exploitation requires the attacker to have access to the affected system, which could lead to service interruptions or crashes.

CVE-2026-28546Medium

This vulnerability allows an attacker to crash the scanning module of HarmonyOS, potentially making the system unavailable. To exploit this, the attacker needs to send specially crafted input to the module, which could happen if the device is connected to a malicious network or application.