CVE-2026-92802
kan through 0.6.0 fails to properly validate board creation permissions in the GitHub project import endpoint, allowing guests to create boards despite lacking board:create permission. Attackers can bypass authorization checks by using the importProjects mutation to create boards while remaining blocked on direct creation paths.
- Published Sep 16, 2026
- CVSS 5.3 medium
- 0.4% chance of exploitation in the next 30 days (EPSS)