CVE-2026-85085CWE-940

CVE-2026-85085

Critical · published September 4, 2026

CVSS v3.1
9.6
EPSS
0%
Percentile
12.6
In the wild
Unconfirmed
What it is

The Canva Android App before 2.376.0 allowed an external origin to be loaded in a privileged WebView. A threat actor who controls the page loaded by the user is able to communicate with Canva using the user’s session.

The record
Technical detail
CVSS v3.1
9.6 · CRITICAL
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:L
CVSS v4.0
Not supplied
EPSS
0.00221 · 12.6th percentile
Weakness
CWE-940 · Improper Verification of Source of a Communication Channel
Published
2026-09-04T11:17Z
References (1)
EPSS history
Timeline
  • 05 SEP 03:44Z
    EPSS moved — → 0%
    epss
  • 04 SEP 06:00Z
    The Canva Android App before 2.376.0 allowed an external origin to be loaded in a privileged WebView
    cvelistv5