CVE-2026-85085

EUVD-2026-70914
The Canva Android App before 2.376.0 allowed an external origin to be loaded in a privileged WebView. A threat actor who controls the page loaded by the user is able to communicate with Canva using the user’s session.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
CanvaCNA
9.6 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:L
Base Score
CVSS 3.x
EPSS Score
Percentile: 12.54%
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
canvacanva
𝑥
< 2.376.0
CNA