CVE-2026-90860
7.1 HIGHPublished 2026-09-21 · Updated 2026-09-21
AI risk analysis
- Summary
- The flaw allows an attacker to access a user’s session by controlling a privileged WebView, posing a high security risk.
- Exploitability
- Exploitation requires control over the WebView and is moderately difficult due to the need for specific conditions to be met.
- Blast radius
- If exploited, it could lead to unauthorized access to user sessions, potentially compromising sensitive data.
- Prioritized remediation
- Update the Canva Mobile App to version v1.15.1 or later to mitigate this vulnerability.
sessionwebviewharmonyosaccess
Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.
NVD description
The Canva Mobile App for HarmonyOS before v1.15.1 did not restrict the headers returned to an external origin running in a privileged WebView. A threat actor with control of the WebView could access a user’s session.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:N
Weaknesses
CWE-212
All references
Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.
Related CVEs
Related by shared AI tags and CWE weakness class. Browse the full archive.