ZeroHour

CVE-2026-81546

mass

Stack-Based Buffer Overflow in Affinity by Canva Allows RCE via Crafted Documents

CVSS 3.1
7.7 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-81546 is a stack-based buffer overflow (CWE-121) in the Affinity by Canva application, caused by inadequate bounds checking when parsing Affinity document files. An attacker triggers it by crafting a malicious Affinity document and convincing a user to open it in the app, consistent with the CVSS vector (AV:L/PR:N/UI:R/AC:H), which requires local delivery and user interaction. Successful exploitation could result in arbitrary code execution in the context of the user running Affinity, with high impact to confidentiality, integrity, and availability. All users running Affinity before version 3.3.0 are affected. There are no known public proof-of-concepts, no reports of in-the-wild exploitation, and the flaw is not listed in CISA KEV.

What to do: Upgrade Affinity to version 3.3.0 (the September 2026 release) or later, and verify the installed version via the app's About/settings screen. Until patched, avoid opening Affinity document files from untrusted or unknown sources, since no workaround for the parser flaw is documented. Monitor vendor advisories for any updates on exploitation status.

Affected
Canva Affinity (Affinity by Canva application)All versions before 3.3.0 (fixed in the 3.3.0 September 2026 release)
Estimated exposure
mass≈3M+ users/installations (Affinity has long reported a multi-million-user creative install base and is now distributed free by Canva) — Estimate based on Affinity's publicly reported multi-million-user base and Canva's free distribution of the app, which plausibly keeps affected installations above one million, though actual counts are not disclosed.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

The Affinity by Canva application before 3.3.0 (September 2026 release) did not perform adequate bounds checking when parsing Affinity document files leading to a stack-based buffer overflow. A threat actor could craft a Affinity document that when opened by a user in Affinity could result in arbitrary code execution.

Weakness
CWE-121
Vector
CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.