CVE-2026-90860
- EPSS 0.18%
- Veröffentlicht 21.09.2026 06:43:02
- Zuletzt bearbeitet 21.09.2026 20:17:39
The Canva Mobile App for HarmonyOS before v1.15.1 did not restrict the headers returned to an external origin running in a privileged WebView. A threat actor with control of the WebView could access a user’s session.
CVE-2026-92839
- EPSS 0.21%
- Veröffentlicht 17.09.2026 03:53:51
- Zuletzt bearbeitet 18.09.2026 17:49:08
Canva Desktop before v1.125.0 performed double decoding in the deeplink handler. A threat actor could cause the application to load arbitrary same-origin content under the user’s session.
CVE-2026-85094
- EPSS 0.23%
- Veröffentlicht 04.09.2026 06:02:47
- Zuletzt bearbeitet 08.09.2026 14:03:48
The Canva Android App before 2.376.0 did not restrict the headers returned to an external origin running in a privileged WebView. A threat actor with control of the WebView could access a user’s session.
CVE-2026-85085
- EPSS 0.22%
- Veröffentlicht 04.09.2026 06:00:46
- Zuletzt bearbeitet 08.09.2026 14:03:48
The Canva Android App before 2.376.0 allowed an external origin to be loaded in a privileged WebView. A threat actor who controls the page loaded by the user is able to communicate with Canva using the user’s session.