CVE-2026-92802 UNKNOWN

CVE-2026-92802

Published: 2026-09-16

Description

kan through 0.6.0 fails to properly validate board creation permissions in the GitHub project import endpoint, allowing guests to create boards despite lacking board:create permission. Attackers can bypass authorization checks by using the importProjects mutation to create boards while remaining blocked on direct creation paths.

AI Intelligence Brief

AI Intelligence

Analyzing vulnerability vectors…