CVE-2026-90860: Canva

High severity, CVSS 7.1. EPSS: 0.3% chance of exploitation in the next 30 days.

The Canva Mobile App for HarmonyOS before v1.15.1 did not restrict the headers returned to an external origin running in a privileged WebView. A threat actor with control of the WebView could access a user’s session.

Affected products

  • Canva Canva: before 1.15.1 (fixed in 1.15.1)

Published 2026-09-21. Last modified 2026-09-21.