Insufficient Ownership Checks in Kurrier API for Webhooks and Identities
CVE-2026-50167

5.3MEDIUM

Key Information:

Status
Vendor
CVE Published:
18 August 2026

What is CVE-2026-50167?

Kurrier, a self-hosted workspace platform for email, calendar, and storage, previously had a vulnerability in its API endpoints that failed to enforce ownership checks for authenticated requests. This flaw allowed attackers with valid API keys to access and enumerate webhook and identity resources belonging to other users. This compromised the confidentiality of sensitive metadata through specific API endpoints, even though anonymous requests and invalid keys were rejected. The issue has been addressed in version 1.2.4, enhancing the security posture of the application.

Affected Version(s)

kurrier < 1.2.4

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.