PT-2026-96044 · Canva · Canva

·

CVE-2026-90860

·

Published

2026-09-21

·

Updated

2026-09-21

CVSS v3.1

7.1

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:N
Name of the Vulnerable Software and Affected Versions Canva Mobile App for HarmonyOS versions prior to 1.15.1
Description The application fails to restrict headers returned to an external origin operating within a privileged WebView. A privileged WebView is a system component that allows the application to display web content. An attacker who controls this WebView could potentially access the user session.
Recommendations Update to version 1.15.1 or later.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-90860

Affected Products

Canva