CVE-2026-92802: kan through 0.6.0 Authorization Bypass via GitHub Project Import

Published Sep 16, 2026
·
Updated

kan through 0.6.0 fails to properly validate board creation permissions in the GitHub project import endpoint, allowing guests to create boards despite lacking board:create permission. Attackers can bypass authorization checks by using the importProjects mutation to create boards while remaining blocked on direct creation paths.

Affected Software

1 affected component
GitHub<=0.6.0

Event History

Sep 16, 2026
CVE Published
via MITRE·08:32 PM
Data Sourced
via MITRE·08:32 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who can exploit this issue?

A guest user who lacks the board:create permission can exploit the affected GitHub project import endpoint. The attacker must be able to invoke the importProjects mutation.

2

Is direct board creation also vulnerable?

No. The available information states that guests remain blocked on direct board creation paths; the authorization bypass occurs through GitHub project import.

3

What should be restricted if an update is not immediately available?

Restrict guest access to the GitHub project import functionality or otherwise prevent untrusted guest users from invoking the importProjects mutation. This removes the identified bypass path while direct board creation controls remain in place.

4

How can administrators identify possible exploitation?

Review boards created through GitHub project imports and check whether their creators were guests or lacked board:create permission. Such board creations indicate use of the affected authorization path.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203