PT-2026-97020 · Kaneo · Kaneo

·

CVE-2026-63104

·

Published

2026-09-22

·

Updated

2026-09-22

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions Kaneo versions 2.3.12 through 2.12.1
Description Authenticated workspace members with viewer or member roles can delete and modify tasks beyond their assigned permissions. This occurs because the 'PATCH /api/task/bulk' endpoint verifies workspace membership but fails to perform the role-based permission checks required by other task endpoints. An attacker can use this endpoint to permanently delete all tasks or modify the status, priority, assignee, due date, and labels of tasks within a workspace.
Recommendations Update Kaneo to version 2.12.2 or later. As a temporary mitigation, restrict access to the 'PATCH /api/task/bulk' endpoint.

Exploit

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-63104
GHSA-GX46-MFGJ-VM86

Affected Products

Kaneo