Header Exposure Vulnerability in Canva Android App
CVE-2026-85094
8.8HIGH
What is CVE-2026-85094?
A security flaw in the Canva Android App prior to version 2.376.0 allows unauthorized access to user sessions through a privileged WebView. This issue arises from inadequate restrictions on headers returned to external origins, enabling threat actors with control over the WebView to exploit user session information.
Affected Version(s)
Canva 0 < 2.376.0
