Vulnerability Bulletins

CVE-2026-92802

   
Affected software GITHUB
 
kan through 0.6.0 fails to properly validate board creation permissions in the GitHub project import endpoint, allowing guests to create boards despite lacking board:create permission. Attackers can bypass authorization checks by using the importProjects mutation to create boards while remaining blocked on direct creation paths.

Link:

https://nvd.nist.gov/vuln/detail/CVE-2026-92802