PT-2026-97020 · Kaneo · Kaneo
CVSS v3.1
8.1
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Kaneo versions 2.3.12 through 2.12.1
Description
Authenticated workspace members with viewer or member roles can delete and modify tasks beyond their assigned permissions. This occurs because the 'PATCH /api/task/bulk' endpoint verifies workspace membership but fails to perform the role-based permission checks required by other task endpoints. An attacker can use this endpoint to permanently delete all tasks or modify the status, priority, assignee, due date, and labels of tasks within a workspace.
Recommendations
Update Kaneo to version 2.12.2 or later.
As a temporary mitigation, restrict access to the 'PATCH /api/task/bulk' endpoint.
Exploit
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Kaneo