PT-2026-85425 · Canva · Canva

·

CVE-2026-85085

·

Published

2026-09-04

·

Updated

2026-09-09

CVSS v3.1

9.6

Critical

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:L
Name of the Vulnerable Software and Affected Versions Canva Android versions prior to 2.376.0
Description An issue exists where an external origin can be loaded within a privileged WebView, a component used to display web content inside a native application. This failure in the origin trust boundary allows a threat actor who controls the loaded page to communicate with the application using the user's session, potentially leading to session hijacking. The exploitation of this flaw requires user interaction.
Recommendations Update Canva Android to version 2.376.0 or later.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-85085

Affected Products

Canva