WebView Vulnerability in Canva Mobile App for HarmonyOS
CVE-2026-90860

7.1HIGH

Key Information:

Vendor

Canva

Status
Vendor
CVE Published:
21 September 2026

What is CVE-2026-90860?

The Canva Mobile App for HarmonyOS prior to version 1.15.1 is susceptible to a vulnerability that allows external origins running in a privileged WebView to access unauthorized data. A malicious actor, having control over the WebView, can potentially retrieve sensitive session information from users, compromising their privacy and app integrity. It is crucial for users to update their applications to the latest version to mitigate this risk.

Affected Version(s)

Canva HarmonyOS 0 < 1.15.1

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
Low
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Wing Cheng (Canva)
Tin Duong (Canva)
.