PatchSiren

kanbn CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM kanbn CVE published 2026-09-16

CVE-2026-92802

CVE-2026-92802 debrief based on CVE Program and NVD records. The kan project through version 0.6.0 has a vulnerability in its GitHub project import endpoint, allowing guests to create boards despite lacking board:create permission. This issue arises from improper validation of board creation permissions, potentially leading to unauthorized board creation. kan users and administrators should assess exposur [truncated]