← Back to CVE List
CVE-2026-81546NVD
Vulnerability Summary
The Affinity by Canva application before 3.3.0 (September 2026 release) did not perform adequate bounds checking when parsing Affinity document files leading to a stack-based buffer overflow. A threat actor could craft a Affinity document that when opened by a user in Affinity could result in arbitrary code execution.
CVSS v3.1 Base Metrics — Score 7.7 (HIGH)
Attack VectorLocal
Attack ComplexityHigh
Privileges RequiredNone
User InteractionRequired
ScopeChanged
ConfidentialityHigh
IntegrityHigh
AvailabilityHigh
Affected & Patched Versions
- Canva Affinity < 3.3.0
- Canva Affinity 3.3.0