MEDIUM
kan through 0.6.0 Authorization Bypass via GitHub Project Import
Published Sep 16, 2026
5.3
MEDIUMCVSS 4.0
EPSS 0.37%
Description
kan through 0.6.0 fails to properly validate board creation permissions in the GitHub project import endpoint, allowing guests to create boards despite lacking board:create permission. Attackers can bypass authorization checks by using the importProjects mutation to create boards while remaining blocked on direct creation paths.
Affected products
-
- Version 0StatusaffectedConstraints<=0.6.0
- Version
No data.
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (6)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-81062 Advisory
- https://github.com/kanbn/kan product
- https://github.com/kanbn/kan/blob/f08920d/packages/api/src/routers/import.ts#L259 technical-description
- https://github.com/kanbn/kan/blob/v0.6.0/packages/api/src/routers/import.ts#L622-L670 technical-description
- https://github.com/kanbn/kan/issues/628 issue-tracking
- https://www.vulncheck.com/advisories/kan-through-0.6.0-authorization-bypass-via-github-project-import third-party-advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-81062 | Advisory | |
| https://github.com/kanbn/kan | product | |
| https://github.com/kanbn/kan/blob/f08920d/packages/api/src/routers/import.ts#L259 | technical-description | |
| https://github.com/kanbn/kan/blob/v0.6.0/packages/api/src/routers/import.ts#L622-L670 | technical-description | |
| https://github.com/kanbn/kan/issues/628 | issue-tracking | |
| https://www.vulncheck.com/advisories/kan-through-0.6.0-authorization-bypass-via-github-project-import | third-party-advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulnCheck
Published Sep 16, 2026
Updated Sep 17, 2026
Reserved Sep 16, 2026
Link CVE-2026-92802
CISA Vulnrichment
Updated Sep 17, 2026
ENISA EUVD
EUVD-2026-81062 Assigner VulnCheck
Published Sep 16, 2026
Updated Sep 17, 2026
Exploited since n/a
Link EUVD-2026-81062