CVE-2026-90860
7.1Canva · Canva Mobile App for HarmonyOS
The Canva Mobile App for HarmonyOS fails to restrict headers returned to external origins in privileged WebViews, potentially allowing session access by unauthorized parties.
Executive summary
A vulnerability in the Canva Mobile App for HarmonyOS allows an attacker to hijack user sessions by exploiting improper header restrictions in a privileged WebView.
Vulnerability
This issue is classified as improper removal of sensitive information before transfer (CWE-212). The application fails to restrict headers returned to external origins within a privileged WebView, allowing an unauthenticated attacker who controls the WebView to gain access to user session data.
Business impact
The compromise of user sessions presents a significant risk to data privacy and account security. An attacker capable of accessing these sessions could potentially impersonate legitimate users, leading to unauthorized access to personal projects and account-related information. With a CVSS score of 7.1, this represents a high-severity risk that demands immediate attention to prevent potential account takeovers.
Remediation
Immediate Action: Update the Canva Mobile App for HarmonyOS to version 1.15.1 or later immediately to apply the necessary header restrictions.
Proactive Monitoring: Review application access logs for unusual patterns or signs of unauthorized session activity originating from external WebView contexts.
Compensating Controls: Ensure that mobile devices are managed through enterprise security policies that restrict the execution of untrusted or external content within privileged application containers.
Exploitation status
Public Exploit Available: No — no confirmed public exploit exists in the available data.
Analyst recommendation
Given the potential for session hijacking, administrators and users must prioritize the update to version 1.15.1. The ability for an attacker to access sensitive session information poses a critical risk to user identity and data integrity, making the rapid deployment of this patch essential.
More Canva CVEs
History
- Disclosed CVE record published
- Collected by CVE Brief via github
- Analyst report written
- Published in the daily brief high section
Sources
Originally found and disclosed by Wing Cheng (Canva), Tin Duong (Canva), per the CVE Program record.