Insufficient Ownership Checks in Kurrier API for Webhooks and Identities
CVE-2026-50167
5.3MEDIUM
What is CVE-2026-50167?
Kurrier, a self-hosted workspace platform for email, calendar, and storage, previously had a vulnerability in its API endpoints that failed to enforce ownership checks for authenticated requests. This flaw allowed attackers with valid API keys to access and enumerate webhook and identity resources belonging to other users. This compromised the confidentiality of sensitive metadata through specific API endpoints, even though anonymous requests and invalid keys were rejected. The issue has been addressed in version 1.2.4, enhancing the security posture of the application.
Affected Version(s)
kurrier < 1.2.4
