Missing Authorization Flaw in Kaneo Task Management Software
CVE-2026-63104
7.2HIGH
What is CVE-2026-63104?
An authorization vulnerability exists in Kaneo that affects authenticated workspace members with viewer or member roles. This flaw allows these users to exploit the bulk task endpoint, which bypasses necessary workspace permission checks. Attackers can issue requests to the PATCH /api/task/bulk endpoint, enabling them to delete or modify tasks, including altering task status, priority, assignee, due date, and labels. Organizations using affected versions should prioritize updating to the latest release to safeguard against potential intrusions.
Affected Version(s)
kaneo 2.3.12 < 2.12.2
