Skip to content
CVE Alert: CVE-2026-63104 – usekaneo

CVE Alert: CVE-2026-63104 – usekaneo

Redpacketsecurity admin September 23, 2026

Kaneo versions 2.3.12 before 2.12.2 contain a missing authorization vulnerability that allows authenticated workspace members with viewer or member roles to delete and modify tasks beyond their assigned permissions by exploiting the bulk task endpoint that omits workspace permission checks. Attackers can send requests to the PATCH /api/task/bulk endpoint, which verifies only workspace membership without calling the role-based permission check enforced on all other task endpoints, to permanently delete all tasks or modify task status, priority, assignee, due date, and labels in a workspace.

High-priority remediation is warranted because a proof-of-concept indicator exists, although there is no evidence here of active exploitation or KEV listing.

A low-privilege workspace account could undermine task integrity and availability without requiring user interaction, causing unauthorised changes or wholesale loss of operational records. Likely attacker objectives include disrupting workflows, manipulating ownership or deadlines, and damaging confidence in project data; confidentiality exposure appears limited.

### Most likely attack path

An attacker needs a valid network-accessible account with basic workspace membership, but no special role, elevated rights or victim interaction. They would send crafted requests to the bulk task function, enabling automated mass modification or deletion within the same workspace; unchanged scope limits direct cross-system privilege escalation, though shared workspaces could facilitate operational disruption.

### Who is most exposed

Internet-accessible self-hosted deployments with numerous members, broad account creation, shared workspaces or integrations that rely on task data are most exposed. Organisations using the platform for incident response, delivery planning or regulated workflows face greater integrity and recovery consequences.

Audit bulk task requests, especially unusual volume or rapid deletion activity.

Alert when viewer/member accounts alter tasks outside their normal ownership.

Correlate API activity with new sessions, atypical IPs and token use.

Check application and database audit trails for mass status, assignee or label changes.

Preserve affected workspace records and authentication logs for investigation.

### Mitigation and prioritisation

Upgrade to the fixed release or later after controlled testing; treat as urgent.

Temporarily restrict access to the bulk-task endpoint at the reverse proxy where feasible.

Review workspace membership, disable unnecessary accounts and enforce MFA.

Back up task data and validate restoration before making changes.

Monitor closely during rollout and apply staged change control for business-critical workspaces.

A considerable amount of time and effort goes into maintaining this website, creating backend automation and creating new features and content for you to make actionable intelligence decisions. Everyone that supports the site helps enable new functionality.

If you like the site, please support us on Patreon or Buy Me A Coffee using the buttons below.

Extracted Entities

Attack Types (1)

Platforms (1)