kan through 0.6.0 fails to properly validate board creation permissions in the GitHub project import endpoint, allowing guests to create boards despite lacking board:create permission. Attackers can bypass authorization checks by using the importProjects mutation to create boards while remaining blocked on direct creation paths.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 16 Sep 2026 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | kan through 0.6.0 fails to properly validate board creation permissions in the GitHub project import endpoint, allowing guests to create boards despite lacking board:create permission. Attackers can bypass authorization checks by using the importProjects mutation to create boards while remaining blocked on direct creation paths. | |
| Title | kan through 0.6.0 Authorization Bypass via GitHub Project Import | |
| First Time appeared |
Kan
Kan kan |
|
| Weaknesses | CWE-862 | |
| CPEs | cpe:2.3:a:kan:kan:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Kan
Kan kan |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-16T20:32:52.568Z
Reserved: 2026-09-16T19:47:13.857Z
Link: CVE-2026-92802
No data.
Status : Received
Published: 2026-09-16T21:17:29.830
Modified: 2026-09-16T21:17:29.830
Link: CVE-2026-92802
No data.
OpenCVE Enrichment
No data.
Weaknesses