CVE-2026-85094

8.8

Canva · Canva

The Canva Android App fails to restrict headers returned to external origins in privileged WebViews, allowing a threat actor to access a user's session.

Executive summary

A critical vulnerability in the Canva Android App allows an attacker to hijack user sessions by exploiting improper header restrictions within a privileged WebView component.

Vulnerability

The application fails to properly remove or restrict sensitive headers when communicating with an external origin inside a privileged WebView. An attacker who can control or influence the content rendered in the WebView can intercept these headers to capture the user's session information.

Business impact

This vulnerability is rated at 8.8, reflecting a high risk of session hijacking and unauthorized account access. If exploited, an attacker could gain full control over a victim's Canva account, leading to the theft of personal designs, sensitive data, and potential misuse of user credentials.

Remediation

Immediate Action: Update the Canva Android App to version 2.376.0 or later via the Google Play Store.

Proactive Monitoring: Users should review their account activity and revoke any suspicious active sessions from the Canva account security settings.

Compensating Controls: Avoid using the Canva mobile app on untrusted networks or accessing untrusted external links while within the app environment until the update is applied.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Mobile application security is vital for protecting user data. Users and administrators of managed mobile devices should ensure the Canva app is updated to version 2.376.0 immediately to prevent session hijacking and protect account integrity.

More Canva CVEs

Sources

Originally found and disclosed by hakupiku (Bugcrowd), per the CVE Program record.