VYPR
Medium severity5.9NVD Advisory· Published May 15, 2026· Updated May 15, 2026

CVE-2026-41961

CVE-2026-41961

Description

Permission control vulnerability in contacts. Impact: Successful exploitation of this vulnerability may affect availability.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

A permission control flaw in the contacts module of Huawei HarmonyOS and EMUI can be exploited to affect device availability.

Vulnerability

A permission control vulnerability exists in the contacts module of Huawei HarmonyOS and EMUI. The flaw is present in HarmonyOS versions 4.0.0, 4.2.0, 4.3.0, 4.3.1, 5.1.0, 6.0.0, 6.1.0 and EMUI versions 14.0.0, 14.2.0, 15.0.0, as listed in the May 2026 security bulletin [1]. Successful exploitation may affect availability.

Exploitation

The description indicates this is a permission control vulnerability in the contacts module [1]. An attacker would likely need local access to the device or the ability to trick a user into performing actions that bypass permission checks. Specific exploitation steps are not detailed in the available references.

Impact

Successful exploitation of this vulnerability may affect the availability of the device [1]. There is no indication of confidentiality or integrity compromise in the description.

Mitigation

Huawei has released security patches in the May 2026 security bulletin [1]. Users should update their devices to the latest firmware versions to mitigate this vulnerability. No workarounds are documented.

AI Insight generated on May 21, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.