CVE-2026-25850 Details
Description
in OpenHarmony v6.0 and prior versions allow a local attacker cause information leak
A vulnerability in OpenHarmony versions 6.0 and prior allows local attackers to leak sensitive information due to improper permission management in the filemanagement_storage_service component.
Users can apply the available patches for this vulnerability in the OpenHarmony-v6.0-Release and OpenHarmony-v5.1.0-Release versions. Instructions for applying the patch can be found in the OpenHarmony filemanagement_storage_service repository.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed May 19, 2026CISA-ADP
Assessed May 19, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://gitcode.com/openharmony/security/tree/master/zh/security-disclosure/2026/2026-05.md | [email protected] | AdvisoryBundleRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-281 | Improper Preservation of Permissions | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| OpenHarmony | OpenHarmony-v5.1.0-Release OpenHarmony-v6.0-Release |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 24, 2026 | CVE Translated | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 19, 2026 | New CVE Received | [email protected] |
Volerion