CVE-2026-85094

The Canva Android App before 2.376.0 did not restrict the headers returned to an external origin running in a privileged WebView. A threat actor with control of the WebView could access a user’s session.
Configurations

No configuration.

History

No history.

Information

Published : 2026-09-04 07:17

Updated : 2026-09-08 14:03


NVD link : CVE-2026-85094

Mitre link : CVE-2026-85094

CVE.ORG link : CVE-2026-85094


JSON object : View

Products Affected

No product.

CWE
CWE-212

Improper Removal of Sensitive Information Before Storage or Transfer