CVE-2026-22882: High severity Canva Affinity vulnerability
An out-of-bounds read vulnerability exists in the EMF functionality of Canva Affinity. By using a specially crafted EMF file, an attacker could exploit this vulnerability to perform an out-of-bounds read, potentially leading to the disclosure of sensitive information.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-22882?
CVE-2026-22882 is considered to have a medium severity due to its potential to disclose sensitive information.
How do I fix CVE-2026-22882?
To fix CVE-2026-22882, users should update Canva Affinity to the latest version that resolves the out-of-bounds read vulnerability.
What type of systems are affected by CVE-2026-22882?
CVE-2026-22882 affects Canva Affinity running on Windows systems up to version 3.1.0.
What kind of attack can exploit CVE-2026-22882?
An attacker can exploit CVE-2026-22882 by using a specially crafted EMF file to perform an out-of-bounds read.
What information can be disclosed due to CVE-2026-22882?
CVE-2026-22882 could potentially lead to the disclosure of sensitive information stored in the affected system.