MEDIUM 5.3 NVD
CVE-2026-92802
kan through 0.6.0 fails to properly validate board creation permissions in the GitHub project import endpoint, allowing guests to create boards despite lacking
kan through 0.6.0 fails to properly validate board creation permissions in the GitHub project import endpoint, allowing guests to create boards despite lacking board:create permission. Attackers can bypass authorization checks by using the importProjects mutation to create boards while remaining blocked on direct creation paths.
References
- https://github.com/kanbn/kan
- https://github.com/kanbn/kan/blob/f08920d/packages/api/src/routers/import.ts#L259
- https://github.com/kanbn/kan/blob/v0.6.0/packages/api/src/routers/import.ts#L622-L670
- https://github.com/kanbn/kan/issues/628
- https://www.vulncheck.com/advisories/kan-through-0.6.0-authorization-bypass-via-github-pro
This medium severity vulnerability with a CVSS score of 5.3 was published on 2026-09-16 via NVD.
vulnfeed aggregates 14597 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.