PatchSiren cyber security CVE debrief
CVE-2026-27648 OpenHarmony CVE debrief
A remote code execution vulnerability in OpenHarmony v6.0 and prior versions allows attackers to execute arbitrary code in pre-installed applications. The vulnerability is classified as CWE-787 (Out-of-bounds Write) with a CVSS 3.1 score of 8.8 (HIGH severity). The attack vector is network-based with low attack complexity, requiring low privileges but no user interaction. The vulnerability was disclosed by OpenHarmony security team and published in the NVD on May 19, 2026. The NVD entry currently shows a status of 'Deferred', indicating the record may be awaiting additional analysis or vendor coordination. Organizations using OpenHarmony v6.0 or earlier should monitor for security updates from the OpenHarmony project.
- Vendor
- OpenHarmony
- Product
- Unknown
- CVSS
- HIGH 8.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-19
- Original CVE updated
- 2026-07-24
- Advisory published
- 2026-05-19
- Advisory updated
- 2026-07-24
Who should care
Organizations deploying OpenHarmony-based devices, IoT manufacturers using OpenHarmony, mobile device management teams, and security teams responsible for embedded/mobile operating system security.
Technical summary
The vulnerability exists in OpenHarmony v6.0 and earlier versions, specifically affecting pre-installed applications. The out-of-bounds write weakness (CWE-787) can be exploited remotely by an attacker with low privileges to achieve arbitrary code execution. The network-based attack vector with low complexity and no required user interaction makes this vulnerability particularly dangerous. Successful exploitation grants high impact across confidentiality, integrity, and availability dimensions.
Defensive priority
HIGH
Recommended defensive actions
- Monitor OpenHarmony security advisories for patch availability
- Review pre-installed application permissions and network exposure
- Apply security updates when released by OpenHarmony project
- Consider network segmentation for OpenHarmony-based devices until patched
Evidence notes
CVSS 3.1 vector: AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H. CWE-787 (Out-of-bounds Write) identified as the primary weakness. Affected versions explicitly stated as OpenHarmony v6.0 and prior.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-27648 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-27648
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-27648 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-27648
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://gitcode.com/openharmony/security/tree/master/zh/security-disclosure/2026/2026-04.md
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.