CVE-2026-20726

An out-of-bounds read vulnerability exists in the EMF functionality of Canva Affinity. By using a specially crafted EMF file, an attacker could exploit this vulnerability to perform an out-of-bounds read, potentially leading to the disclosure of sensitive information.
Configurations

Configuration 1 (hide)

cpe:2.3:a:canva:affinity:*:*:*:*:*:windows:*:*

History

19 Mar 2026, 12:12

Type Values Removed Values Added
References () https://talosintelligence.com/vulnerability_reports/TALOS-2025-2324 - () https://talosintelligence.com/vulnerability_reports/TALOS-2025-2324 - Exploit, Third Party Advisory
References () https://trust.canva.com/?tcuUid=1f728b0d-17f3-4c9c-97e9-6662b769eb62 - () https://trust.canva.com/?tcuUid=1f728b0d-17f3-4c9c-97e9-6662b769eb62 - Vendor Advisory
References () https://www.talosintelligence.com/vulnerability_reports/TALOS-2025-2324 - () https://www.talosintelligence.com/vulnerability_reports/TALOS-2025-2324 - Exploit, Third Party Advisory
First Time Canva
Canva affinity
CPE cpe:2.3:a:canva:affinity:*:*:*:*:*:windows:*:*

18 Mar 2026, 14:52

Type Values Removed Values Added
Summary
  • (es) Una vulnerabilidad de lectura fuera de límites existe en la funcionalidad EMF de Canva Affinity. Al usar un archivo EMF especialmente diseñado, un atacante podría explotar esta vulnerabilidad para realizar una lectura fuera de límites, lo que podría llevar a la divulgación de información sensible.

17 Mar 2026, 21:16

Type Values Removed Values Added
References
  • () https://www.talosintelligence.com/vulnerability_reports/TALOS-2025-2324 -

17 Mar 2026, 19:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-17 19:16

Updated : 2026-03-19 12:12


NVD link : CVE-2026-20726

Mitre link : CVE-2026-20726

CVE.ORG link : CVE-2026-20726


JSON object : View

Products Affected

canva

  • affinity
CWE
CWE-125

Out-of-bounds Read