SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-85094

HIGH · CVSS 8.8 EPSS 0.23%

Source: NVD + CISA KEV + EPSS · Published 2026-09-04 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

The Canva Android App prior to version 2.376.0 is vulnerable due to insufficient restrictions on headers returned to an external origin within a privileged WebView. This flaw allows a threat actor controlling the WebView to access a user's session, potentially leading to unauthorized access to sensitive information. Android app developers and organizations using this app should prioritize remediation to protect user data from exploitation.

CVE
CVE-2026-85094
Severity
HIGH
CVSS
8.8
EPSS
0.23%
Android

Original NVD Description

The Canva Android App before 2.376.0 did not restrict the headers returned to an external origin running in a privileged WebView. A threat actor with control of the WebView could access a user’s session.