πŸ” CVE Alert

CVE-2026-90860

HIGH 7.1
CVSS Score
7.1
EPSS Score
0.0%
EPSS Percentile
0th

The Canva Mobile App for HarmonyOS before v1.15.1 did not restrict the headers returned to an external origin running in a privileged WebView. A threat actor with control of the WebView could access a user’s session.

CWE CWE-212
Vendor canva
Product canva
Published Sep 21, 2026
Stay Ahead of the Next One

Get instant alerts for canva canva

Be the first to know when new high vulnerabilities affecting canva canva are published β€” delivered to Slack, Telegram or Discord.

Get Free Alerts β†’ Free Β· No credit card Β· 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Unchanged
Confidentiality
Low
Integrity
High
Availability
None

Affected Versions

Canva / Canva
0 < 1.15.1

References

NVD β†— CVE.org β†— EPSS Data β†—
trust.canva.com: https://trust.canva.com?tcuUid=c17214e0-e758-4472-8238-abeb79faff07

Credits

Wing Cheng (Canva) Tin Duong (Canva)