9.6
CVE-2026-85085
- EPSS 0.22%
- Veröffentlicht 04.09.2026 06:00:46
- Zuletzt bearbeitet 08.09.2026 14:03:48
- Erkennungen
The Canva Android App before 2.376.0 allowed an external origin to be loaded in a privileged WebView. A threat actor who controls the page loaded by the user is able to communicate with Canva using the user’s session.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerCanva
≫
Produkt
Canva
Default Statusaffected
Version
0
Version <
2.376.0
Status
affected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.22% | 0.125 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| 61adb53e-e4b3-47f7-8a93-4717c9e77dc6 | 9.6 | 2.8 | 6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:L
|
CWE-940 Improper Verification of Source of a Communication Channel
The product establishes a communication channel to handle an incoming request that has been initiated by an actor, but it does not properly verify that the request is coming from the expected origin.
https://trust.canva.com/?tcuUid=be2ebc32-7053-4885-bf71-68771aa4589a