CVE-2026-63104 Details
Description
Kaneo versions 2.3.12 before 2.12.2 contain a missing authorization vulnerability that allows authenticated workspace members with viewer or member roles to delete and modify tasks beyond their assigned permissions by exploiting the bulk task endpoint that omits workspace permission checks. Attackers can send requests to the PATCH /api/task/bulk endpoint, which verifies only workspace membership without calling the role-based permission check enforced on all other task endpoints, to permanently delete all tasks or modify task status, priority, assignee, due date, and labels in a workspace.
A missing authorization vulnerability has been identified in Kaneo versions 2.3.12 prior to 2.12.2. This vulnerability allows authenticated workspace members with viewer or member roles to delete and modify tasks beyond their assigned permissions. The issue arises from the bulk task endpoint, which fails to implement proper workspace permission checks. Attackers can exploit the PATCH /api/task/bulk endpoint, which only verifies workspace membership, to permanently delete tasks or alter task details such as status, priority, assignee, due date, and labels within a workspace.
The vulnerability has been patched in Kaneo version 2.12.2. Users should update to this version to address the issue.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 22, 2026CISA-ADP
Assessed Sep 22, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/usekaneo/kaneo/security/advisories/GHSA-gx46-mfgj-vm86 | CISA-ADP | AdvisoryExploitRemedyVendor |
| https://github.com/usekaneo/kaneo/releases/tag/v2.12.2 | [email protected] | Release NotesVendor |
| https://github.com/usekaneo/kaneo/security/advisories/GHSA-gx46-mfgj-vm86 | [email protected] | AdvisoryExploitRemedyVendor |
| https://www.vulncheck.com/advisories/kaneo-missing-authorization-via-bulk-task-endpoint | [email protected] | Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-862 | Missing Authorization | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Kaneo | >= 2.3.12, < 2.12.2 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 22, 2026 | New CVE Received | [email protected] |
| Sep 22, 2026 | CVE Modified | CISA-ADP |
Volerion