Junglewise Threat Intelligence

CVE-2026-63104: Kaneo missing authorization in bulk task endpoint

CVE-2026-63104 · Severity: high · CVSS 8.1 · Published 2026-09-22

Executive brief

Kaneo is a project management and task collaboration platform. A flaw in its bulk task API allows authenticated workspace members with lower-privilege roles (viewer or member) to delete all tasks or modify task properties they should not have access to, causing permanent data loss or workflow disruption. An attacker need only be added to a workspace to execute this attack.

Technical details

The PATCH /api/task/bulk endpoint omits role-based permission checks (requireWorkspacePermission) that are enforced on all other task endpoints, verifying only workspace membership. Authenticated attackers with viewer or member roles can send bulk requests to delete tasks or modify status, priority, assignee, due date, and labels. Patch 2.12.2 adds the missing permission checks keyed to each operation (task:delete for delete, task:assign for assignee updates, etc.).

Affected products

  • Kaneo Kaneo 2.3.12 to 2.12.1

Timeline

  • 2026-09-21: disclosed
  • 2026-08-04: patched: v2.12.2 released with fix

References