CVE-2026-81546
massStack-Based Buffer Overflow in Affinity by Canva Allows RCE via Crafted Documents
CVE-2026-81546 is a stack-based buffer overflow (CWE-121) in the Affinity by Canva application, caused by inadequate bounds checking when parsing Affinity document files. An attacker triggers it by crafting a malicious Affinity document and convincing a user to open it in the app, consistent with the CVSS vector (AV:L/PR:N/UI:R/AC:H), which requires local delivery and user interaction. Successful exploitation could result in arbitrary code execution in the context of the user running Affinity, with high impact to confidentiality, integrity, and availability. All users running Affinity before version 3.3.0 are affected. There are no known public proof-of-concepts, no reports of in-the-wild exploitation, and the flaw is not listed in CISA KEV.
What to do: Upgrade Affinity to version 3.3.0 (the September 2026 release) or later, and verify the installed version via the app's About/settings screen. Until patched, avoid opening Affinity document files from untrusted or unknown sources, since no workaround for the parser flaw is documented. Monitor vendor advisories for any updates on exploitation status.
| Canva Affinity (Affinity by Canva application) | All versions before 3.3.0 (fixed in the 3.3.0 September 2026 release) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
The Affinity by Canva application before 3.3.0 (September 2026 release) did not perform adequate bounds checking when parsing Affinity document files leading to a stack-based buffer overflow. A threat actor could craft a Affinity document that when opened by a user in Affinity could result in arbitrary code execution.
- Weakness
- CWE-121
- Vector
- CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.