CVE-2026-90860: Canva
High severity, CVSS 7.1. EPSS: 0.3% chance of exploitation in the next 30 days.
The Canva Mobile App for HarmonyOS before v1.15.1 did not restrict the headers returned to an external origin running in a privileged WebView. A threat actor with control of the WebView could access a user’s session.
Affected products
- Canva Canva: before 1.15.1 (fixed in 1.15.1)
Published 2026-09-21. Last modified 2026-09-21.