Buffer Overflow Vulnerability in Affinity by Canva Application
CVE-2026-81546

7.7HIGH

Key Information:

Vendor

Canva

Status
Vendor
CVE Published:
17 September 2026

What is CVE-2026-81546?

The Affinity application developed by Canva prior to version 3.3.0 contains a vulnerability due to insufficient bounds checking when processing Affinity document files. This flaw can be exploited by threat actors who craft malicious Affinity documents. If these documents are opened by users of the application, it could potentially lead to arbitrary code execution, allowing attackers to manipulate the system or steal sensitive information.

Affected Version(s)

Affinity 0 < 3.3.0

References

CVSS V3.1

Score:
7.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Angus Cornall (Canva)
.