PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-81546 Canva CVE debrief

CVE-2026-81546 is a high-severity vulnerability in the Affinity by Canva application, allowing arbitrary code execution via crafted Affinity documents due to inadequate bounds checking, leading to a stack-based buffer overflow. The vulnerability affects users who open Affinity documents from untrusted sources. Defenders should prioritize verifying and updating to version 3.3.0 or later, assessing exposure, and implementing compensating controls. This vulnerability has a high CVSS score of 7.7, emphasizing the need for immediate attention.

Vendor
Canva
Product
Affinity
CVSS
HIGH 7.7
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-17
Original CVE updated
2026-09-18
Advisory published
2026-09-17
Advisory updated
2026-09-18

Who should care

Defenders responsible for managing and securing the Affinity by Canva application, as well as users who open Affinity documents from untrusted sources, should be aware of this vulnerability and take necessary precautions.

Why it matters

CVE-2026-81546 is a high-severity vulnerability in the Affinity by Canva application that could allow arbitrary code execution via crafted Affinity documents. Defenders should prioritize verifying and updating to version 3.3.0 or later, assessing exposure, and implementing compensating controls.

  • Potential for arbitrary code execution
  • Need for version verification and updates
  • Importance of monitoring for suspicious Affinity documents

Technical summary

The Affinity by Canva application before version 3.3.0 did not perform adequate bounds checking when parsing Affinity document files, leading to a stack-based buffer overflow. A threat actor could craft a malicious Affinity document that, when opened by a user in Affinity, could result in arbitrary code execution. The vulnerability has a high CVSS score of 7.7, emphasizing the need for immediate attention and mitigation. Defenders should prioritize verifying and updating to version 3.3.0 or later, assessing exposure, and implementing compensating controls.

Defensive priority

Defenders should prioritize verifying and updating to version 3.3.0 or later of the Affinity by Canva application, assessing exposure, and implementing compensating controls.

Recommended defensive actions

  • Verify and update to version 3.3.0 or later of the Affinity by Canva application
  • Assess exposure and implement compensating controls
  • Monitor for suspicious Affinity document files
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up

Evidence notes

The CVE record and NVD entry provide details on the vulnerability, including its high CVSS score of 7.7 and the potential for arbitrary code execution. The Affinity by Canva application before version 3.3.0 did not perform adequate bounds checking when parsing Affinity document files, leading to a stack-based buffer overflow. The vulnerability allows threat actors to craft malicious Affinity documents that can result in arbitrary code execution when opened by a user in Affinity.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-81546 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-81546

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-81546 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-81546

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.