{"id":"CVE-2026-90860","published":"2026-09-21T07:16:53.463","lastModified":"2026-09-21T20:17:39.220","description":"The Canva Mobile App for HarmonyOS before v1.15.1 did not restrict the headers returned to an external origin running in a privileged WebView. A threat actor with control of the WebView could access a user’s session.","cvssScore":7.1,"cvssSeverity":"HIGH","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:N","cwes":["CWE-212"],"vendors":[],"products":[],"references":[{"url":"https://trust.canva.com?tcuUid=c17214e0-e758-4472-8238-abeb79faff07","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":{"summary":"The flaw allows an attacker to access a user’s session by controlling a privileged WebView, posing a high security risk.","exploitability":"Exploitation requires control over the WebView and is moderately difficult due to the need for specific conditions to be met.","blast_radius":"If exploited, it could lead to unauthorized access to user sessions, potentially compromising sensitive data.","remediation":"Update the Canva Mobile App to version v1.15.1 or later to mitigate this vulnerability.","tags":["session","webview","harmonyos","access"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-09-22T06:17:11.919Z"}}