CVE-2026-31368 Details
Description
AiAssistant is affected by type privilege bypass, successful exploitation of this vulnerability may affect service availability.
A privilege bypass vulnerability has been identified in Honor AiAssistant. Successful exploitation of this vulnerability may disrupt service availability. The issue affects AiAssistant versions prior to 90.0.12.010.
Users can update to Honor AiAssistant version 90.0.12.010 to address this vulnerability. For products that support automatic updates, a system update prompt will be available.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Apr 21, 2026CISA-ADP
Assessed Apr 21, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.honor.com/global/security/cve-2026-31368/ | Honor Device Co., Ltd. | AdvisoryRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-269 | Improper Privilege Management | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| Honor AiAssistant | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | Honor Device Co., Ltd. |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 10, 2026 | CVE Modified | CISA-ADP |
| Apr 21, 2026 | New CVE Received | Honor Device Co., Ltd. |
Volerion