Kaneo · Kaneo · CVE-2026-63104
**Name of the Vulnerable Software and Affected Versions**
Kaneo versions 2.3.12 through 2.12.1
**Description**
Authenticated workspace members with viewer or member roles can delete and modify tasks beyond their assigned permissions. This occurs because the 'PATCH /api/task/bulk' endpoint verifies workspace membership but fails to perform the role-based permission checks required by other task endpoints. An attacker can use this endpoint to permanently delete all tasks or modify the status, priority, assignee, due date, and labels of tasks within a workspace.
**Recommendations**
Update Kaneo to version 2.12.2 or later.
As a temporary mitigation, restrict access to the 'PATCH /api/task/bulk' endpoint.