OCTOBER 10, 2026
Live Feed
Back to database
Case File

CVE-2026-63104

HIGH · CVSS 8.1 EPSS 0.49% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-22 · Last synced 2026-10-10

CyberRota Analysis

AI-Generated

Kaneo versions prior to 2.12.2 are vulnerable due to a missing authorization check in the bulk task endpoint, allowing authenticated users with limited roles to delete or modify tasks beyond their permissions. This vulnerability can lead to unauthorized task deletions and modifications, potentially disrupting workflows and data integrity within the workspace. Organizations using affected versions should prioritize patching to mitigate the risk of internal abuse and maintain proper access controls.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-63104
Severity
HIGH
CVSS
8.1
EPSS
0.49%

Original NVD Description

Kaneo versions 2.3.12 before 2.12.2 contain a missing authorization vulnerability that allows authenticated workspace members with viewer or member roles to delete and modify tasks beyond their assigned permissions by exploiting the bulk task endpoint that omits workspace permission checks. Attackers can send requests to the PATCH /api/task/bulk endpoint, which verifies only workspace membership without calling the role-based permission check enforced on all other task endpoints, to permanently delete all tasks or modify task status, priority, assignee, due date, and labels in a workspace.