Description
The Affinity by Canva application before 3.3.0 (September 2026 release) did not perform adequate bounds checking when parsing Affinity document files leading to a stack-based buffer overflow. A threat actor could craft a Affinity document that when opened by a user in Affinity could result in arbitrary code execution.
Published: 2026-09-17
Score: 7.7 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution via Stack-Based Buffer Overflow
Action: Immediate Patch
AI Analysis

Impact

Affinity by Canva, a document editing application, has a stack-based buffer overflow in its document parser. The application fails to enforce bounds checking when handling Affinity document files, allowing an attacker to craft a malicious file that, when opened by a user, can execute arbitrary code on the victim’s machine.

Affected Systems

The vulnerability exists in all versions of Affinity prior to 3.3.0 released in September 2026. Users running the affected Canva Affinity application on any operating system that supports the program are at risk if they open malicious documents.

Risk and Exploitability

The CVSS score of 7.7 indicates a high impact, while the EPSS score of less than 1% suggests a currently low likelihood of exploitation. The flaw is not listed in the CISA KEV catalog. Attackers would need to supply a crafted Affinity file to the victim, typically through social engineering or malicious email attachments. Successful exploitation grants arbitrary code execution within the context of the document viewer process.

Generated by OpenCVE AI on September 17, 2026 at 22:20 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update Affinity to version 3.3.0 or newer. This is the official fix for the buffer overflow.
  • Ensure that only trusted documents are opened; display a warning for unknown or network‑downloaded files.
  • Apply a network or endpoint security policy to block or quarantine files with the Affinity document extension from untrusted sources.

Generated by OpenCVE AI on September 17, 2026 at 22:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 02:00:00 +0000

Type Values Removed Values Added
Description The Affinity by Canva application before 3.3.0 (September 2026 release) did not perform adequate bounds checking when parsing Affinity document files leading to a stack-based buffer overflow. A threat actor could craft a Affinity document that when opened by a user in Affinity could result in arbitrary code execution.
First Time appeared Canva
Canva affinity
Weaknesses CWE-121
CPEs cpe:2.3:a:canva:affinity:*:*:*:*:*:*:*:*
Vendors & Products Canva
Canva affinity
References
Metrics cvssV3_1

{'score': 7.7, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Canva

Published:

Updated: 2026-09-17T13:02:52.427Z

Reserved: 2026-08-27T00:19:24.496Z

Link: CVE-2026-81546

cve-icon Vulnrichment

Updated: 2026-09-17T13:02:49.403Z

cve-icon NVD

Status : Deferred

Published: 2026-09-17T02:16:27.537

Modified: 2026-09-18T17:49:08.457

Link: CVE-2026-81546

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T22:45:06Z

Weaknesses
  • CWE-121

    Stack-based Buffer Overflow