PT-2026-94134 · Canva · Affinity

·

CVE-2026-81546

·

Published

2026-09-17

·

Updated

2026-09-17

CVSS v3.1

7.7

High

VectorAV:L/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Affinity by Canva versions prior to 3.3.0
Description Insufficient bounds checking during the parsing of Affinity document files leads to a stack-based buffer overflow. This occurs when the application processes a specially crafted document, which can allow a threat actor to achieve arbitrary code execution on the system.
Recommendations Update to version 3.3.0 or later.

Fix

Stack Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-81546

Affected Products

Affinity