CVE-2026-92839: Medium severity Canva Canva Desktop vulnerability
Published Sep 17, 2026
·Updated
Canva Desktop before v1.125.0 performed double decoding in the deeplink handler. A threat actor could cause the application to load arbitrary same-origin content under the user’s session.
Affected Software
1 affected component
Canva Canva Desktop<1.125.0
Event History
Sep 17, 2026
CVE Published
via MITRE·03:53 AM
Data Sourced
via MITRE·03:53 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What does an attacker need to exploit this issue?
The attacker needs to get a user to interact with a crafted deeplink. No privileges are required, and the attack can be carried out remotely.
2
Which installations are affected?
Canva Desktop versions before v1.125.0 are affected. Updating to v1.125.0 or later addresses the double-decoding behavior in the deeplink handler.
3
What could exploitation allow?
An attacker could cause Canva Desktop to load arbitrary same-origin content using the affected user's session. The reported impact is limited to integrity; no confidentiality or availability impact is specified.