
CVE-2026-27648 in OpenHarmony v6.0 and prior versions allow a remote attacker arbitrary code execution in pre-installed apps. https://www.cve.org/CVERecord?id=CVE-2026-27648
Post summary
CVE-2026-27648 allows remote attackers to execute arbitrary code in OpenHarmony v6.0 and earlier pre-installed apps; no PoC, exploit, or patch info is provided.

