CVE-2026-20726: High severity Canva Affinity vulnerability
An out-of-bounds read vulnerability exists in the EMF functionality of Canva Affinity. By using a specially crafted EMF file, an attacker could exploit this vulnerability to perform an out-of-bounds read, potentially leading to the disclosure of sensitive information.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-20726?
CVE-2026-20726 has a high severity rating due to the potential for sensitive information disclosure.
How do I fix CVE-2026-20726?
To mitigate CVE-2026-20726, users should update Canva Affinity to the latest version, ensuring they are above version 3.1.0.
What type of vulnerability is CVE-2026-20726?
CVE-2026-20726 is classified as an out-of-bounds read vulnerability.
What software is affected by CVE-2026-20726?
CVE-2026-20726 affects Canva Affinity, specifically versions up to 3.1.0 on Windows.
What could an attacker achieve by exploiting CVE-2026-20726?
An attacker exploiting CVE-2026-20726 could read sensitive information from memory due to the out-of-bounds access.