rootpwn

high · CVSS v3 7.7

CVE-2026-81546

Affinity by Canva versions prior to 3.3.0 are vulnerable to a stack-based buffer overflow when parsing Affinity document files. An attacker

Overview

Affinity by Canva versions prior to 3.3.0 are vulnerable to a stack-based buffer overflow when parsing Affinity document files. An attacker can craft a malicious file that, when opened, may allow arbitrary code execution on the victim’s machine.

Description

The Affinity by Canva application before 3.3.0 (September 2026 release) did not perform adequate bounds checking when parsing Affinity document files leading to a stack-based buffer overflow. A threat actor could craft a Affinity document that when opened by a user in Affinity could result in arbitrary code execution.

Impact

If exploited, an attacker can gain code execution privileges, potentially compromising the confidentiality, integrity, and availability of the affected system. This could lead to data theft, unauthorized modifications, or full system takeover.

Remediation

['Upgrade to Affinity 3.3.0 or later, which includes proper bounds checking.', 'Apply any vendor-supplied patches as soon as they are released.', 'Restrict users from opening unknown or untrusted Affinity files.', 'Run Affinity in a sandboxed or least‑privilege environment.', 'Enable application whitelisting and monitor for anomalous process activity.']

Risk context

The CVSS v3 score of 7.7 indicates a high severity vulnerability with the potential for remote code execution. No EPSS data is available, but the lack of bounds checking makes this a critical issue for users of pre‑3.3.0 Affinity products.

Affected products

  • Affinity Designer
  • Affinity Photo
  • Affinity Publisher
  • Affinity by Canva

Scores

Severity
high
CVSS v2
6.2
CVSS v3
7.7
CVSS v4
EPSS

buffer-overflow stack arbitrary-code-execution file-parsing Affinity Canva high-severity

← All CVEs