OCTOBER 10, 2026
Live Feed
Back to database
Case File

CVE-2026-90860

HIGH · CVSS 7.1 EPSS 0.30%

Source: NVD + CISA KEV + EPSS · Published 2026-09-21 · Last synced 2026-10-10

CyberRota Analysis

AI-Generated

The Canva Mobile App for HarmonyOS versions prior to 1.15.1 is vulnerable due to insufficient restrictions on headers returned to an external origin within a privileged WebView. This flaw allows a threat actor controlling the WebView to potentially access sensitive user session information. Organizations using this app should prioritize updates to mitigate the risk of session hijacking and protect user data.

CVE
CVE-2026-90860
Severity
HIGH
CVSS
7.1
EPSS
0.30%

Original NVD Description

The Canva Mobile App for HarmonyOS before v1.15.1 did not restrict the headers returned to an external origin running in a privileged WebView. A threat actor with control of the WebView could access a user’s session.