high · CVSS v3 7.7
CVE-2026-81546
Affinity by Canva versions prior to 3.3.0 are vulnerable to a stack-based buffer overflow when parsing Affinity document files. An attacker
Overview
Affinity by Canva versions prior to 3.3.0 are vulnerable to a stack-based buffer overflow when parsing Affinity document files. An attacker can craft a malicious file that, when opened, may allow arbitrary code execution on the victim’s machine.
Description
The Affinity by Canva application before 3.3.0 (September 2026 release) did not perform adequate bounds checking when parsing Affinity document files leading to a stack-based buffer overflow. A threat actor could craft a Affinity document that when opened by a user in Affinity could result in arbitrary code execution.
Impact
If exploited, an attacker can gain code execution privileges, potentially compromising the confidentiality, integrity, and availability of the affected system. This could lead to data theft, unauthorized modifications, or full system takeover.
Remediation
['Upgrade to Affinity 3.3.0 or later, which includes proper bounds checking.', 'Apply any vendor-supplied patches as soon as they are released.', 'Restrict users from opening unknown or untrusted Affinity files.', 'Run Affinity in a sandboxed or least‑privilege environment.', 'Enable application whitelisting and monitor for anomalous process activity.']
Risk context
The CVSS v3 score of 7.7 indicates a high severity vulnerability with the potential for remote code execution. No EPSS data is available, but the lack of bounds checking makes this a critical issue for users of pre‑3.3.0 Affinity products.
Affected products
- Affinity Designer
- Affinity Photo
- Affinity Publisher
- Affinity by Canva
Scores
- Severity
- high
- CVSS v2
- 6.2
- CVSS v3
- 7.7
- CVSS v4
- —
- EPSS
- —