CVE-2026-85094
EUVD-2026-7091504.09.2026, 07:17
The Canva Android App before 2.376.0 did not restrict the headers returned to an external origin running in a privileged WebView. A threat actor with control of the WebView could access a user’s session.Enginsight
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| canva | canva | 𝑥 < 2.376.0 | CNA |