CyberRota Analysis
AI-GeneratedKaneo versions prior to 2.12.2 are vulnerable due to a missing authorization check in the bulk task endpoint, allowing authenticated users with limited roles to delete or modify tasks beyond their permissions. This vulnerability can lead to unauthorized task deletions and modifications, potentially disrupting workflows and data integrity within the workspace. Organizations using affected versions should prioritize patching to mitigate the risk of internal abuse and maintain proper access controls.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Kaneo versions 2.3.12 before 2.12.2 contain a missing authorization vulnerability that allows authenticated workspace members with viewer or member roles to delete and modify tasks beyond their assigned permissions by exploiting the bulk task endpoint that omits workspace permission checks. Attackers can send requests to the PATCH /api/task/bulk endpoint, which verifies only workspace membership without calling the role-based permission check enforced on all other task endpoints, to permanently delete all tasks or modify task status, priority, assignee, due date, and labels in a workspace.