Missing Authorization Flaw in Kaneo Task Management Software
CVE-2026-63104

7.2HIGH

Key Information:

Vendor

Usekaneo

Status
Vendor
CVE Published:
22 September 2026

What is CVE-2026-63104?

An authorization vulnerability exists in Kaneo that affects authenticated workspace members with viewer or member roles. This flaw allows these users to exploit the bulk task endpoint, which bypasses necessary workspace permission checks. Attackers can issue requests to the PATCH /api/task/bulk endpoint, enabling them to delete or modify tasks, including altering task status, priority, assignee, due date, and labels. Organizations using affected versions should prioritize updating to the latest release to safeguard against potential intrusions.

Affected Version(s)

kaneo 2.3.12 < 2.12.2

References

CVSS V4

Score:
7.2
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Caleb Finley
VulnCheck
.