CVE-2026-34853 is a permission bypass vulnerability affecting the LBS (Location-Based Services) module that allows unauthenticated attackers to circumvent access controls. The vulnerability carries a CVSS score of 7.5 (HIGH) with a network-based attack vector requiring low complexity and no user interaction, making it relatively straightforward to exploit remotely. The primary impact is on availability, as successful exploitation could disrupt service functionality, though confidentiality and integrity are not compromised. The vulnerability currently has a low exploitation probability score (EPSS 0.000050000) and is not listed on the CISA Known Exploited Vulnerabilities catalog, indicating no active exploitation in the wild at this time. With a FAUCET Risk Score of 48/100 and inactive status on industry hot lists, this represents a moderate-priority vulnerability requiring patching but not suggesting imminent widespread attacks.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
4.0.0CPE matchmatch criteria | cpe:2.3:o:huawei:harmonyos:4.0.0:*:*:*:*:*:*:* | ||
4.2.0CPE matchmatch criteria | cpe:2.3:o:huawei:harmonyos:4.2.0:*:*:*:*:*:*:* | ||
4.3.0CPE matchmatch criteria | cpe:2.3:o:huawei:harmonyos:4.3.0:*:*:*:*:*:*:* | ||
4.3.1CPE matchmatch criteria | cpe:2.3:o:huawei:harmonyos:4.3.1:*:*:*:*:*:*:* | ||
14.0.0CPE matchmatch criteria | cpe:2.3:o:huawei:emui:14.0.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.