Junglewise Threat Intelligence

CVE-2026-90860: Canva Mobile App for HarmonyOS header restriction bypass in WebView

CVE-2026-90860 · Severity: high · CVSS 7.1 · Published 2026-09-21

Executive brief

The Canva mobile app for HarmonyOS versions before 1.15.1 failed to restrict HTTP headers returned to external origins within a privileged WebView component. An attacker with control of the WebView could exploit this to steal session credentials and hijack a user's account, gaining unauthorized access to their design files and account data.

Technical details

A header restriction bypass vulnerability in the Canva HarmonyOS app's WebView allows an attacker controlling the WebView to read sensitive response headers—including session tokens—from cross-origin requests. The vulnerability requires the attacker to control the WebView context, a precondition that could be met through other compromises. No authentication bypass is required once this control is established; the impact is full session compromise.

Affected products

  • Canva Mobile App for HarmonyOS before 1.15.1

Timeline

  • 2026-09-21: disclosed

References