CVE-2025-26693: security_access_token has an improper preservation of permissions vulnerability
in OpenHarmony v5.0.3 and prior versions allow a local attacker cause information leak through get permission.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-26693?
CVE-2025-26693 has been classified as a medium severity vulnerability due to its potential for information leakage.
How does CVE-2025-26693 affect OpenHarmony?
CVE-2025-26693 allows a local attacker to exploit permission management features in OpenHarmony versions up to 5.0.3, leading to potential unauthorized information disclosure.
How do I fix CVE-2025-26693?
To mitigate CVE-2025-26693, upgrade your OpenHarmony installation to a version later than 5.0.3 where the vulnerability has been resolved.
Who is affected by CVE-2025-26693?
Users of OpenHarmony version 5.0.3 and earlier are affected by CVE-2025-26693 and should take immediate action to upgrade.
What is the cause of CVE-2025-26693?
CVE-2025-26693 is caused by improper permission handling in OpenHarmony that allows local attackers to leak sensitive information.