CVE-2026-63104

Source
https://cve.org/CVERecord?id=CVE-2026-63104
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-63104.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-63104
Aliases
  • GHSA-gx46-mfgj-vm86
Published
2026-09-22T19:34:24Z
Modified
2026-09-24T03:45:44Z
Severity
  • 7.2 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N CVSS Calculator
Summary
Kaneo 2.3.12 < 2.12.2 Missing Authorization via Bulk Task Endpoint
Details

Kaneo versions 2.3.12 before 2.12.2 contain a missing authorization vulnerability that allows authenticated workspace members with viewer or member roles to delete and modify tasks beyond their assigned permissions by exploiting the bulk task endpoint that omits workspace permission checks. Attackers can send requests to the PATCH /api/task/bulk endpoint, which verifies only workspace membership without calling the role-based permission check enforced on all other task endpoints, to permanently delete all tasks or modify task status, priority, assignee, due date, and labels in a workspace.

Database specific
{
    "cna_assigner":  "VulnCheck",
    "cwe_ids":  [
        "CWE-862"
    ],
    "osv_generated_from":  "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/63xxx/CVE-2026-63104.json"
}
References

Affected packages

Git / github.com/usekaneo/kaneo

Affected ranges

Type
GIT
Repo
https://github.com/usekaneo/kaneo
Events
Database specific
Show details
{
    "extracted_events":  [
        {
            "introduced":  "2.3.12"
        },
        {
            "fixed":  "2.12.2"
        }
    ],
    "source":  [
        "AFFECTED_FIELD",
        "DESCRIPTION",
        "REFERENCES"
    ]
}

Affected versions

mcp-v0.*
mcp-v0.1.6
mcp-v0.1.7
mcp-v0.1.8
v2.*
v2.10.0
v2.11.0
v2.12.0
v2.12.1
v2.3.12
v2.3.14
v2.3.15
v2.3.16
v2.4.0
v2.4.1
v2.4.2
v2.4.3
v2.4.4
v2.5.0
v2.5.1
v2.5.2
v2.5.3
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.6.5
v2.6.6
v2.6.7
v2.6.8
v2.6.9
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.7.4
v2.7.5
v2.7.6
v2.7.7
v2.7.8
v2.8.0
v2.9.0
v2.9.1
v2.9.10
v2.9.2
v2.9.3
v2.9.4
v2.9.5
v2.9.6
v2.9.7
v2.9.8
v2.9.9

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-63104.json"