PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-50167 kurrier-org CVE debrief

CVE-2026-50167 is a vulnerability in Kurrier, a self-hosted workspace for email, calendar, contacts, and storage. Prior to version 1.2.4, the Kurrier API did not enforce ownership checks for authenticated requests when listing and retrieving webhook and identity resources. This could allow an attacker with a valid API key to read and enumerate resources belonging to another account.

Vendor
kurrier-org
Product
kurrier
CVSS
MEDIUM 5.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-18
Original CVE updated
2026-09-18
Advisory published
2026-08-18
Advisory updated
2026-09-18

Who should care

Defenders responsible for Kurrier installations, API key management, and security monitoring should be aware of this vulnerability and take necessary actions to protect their systems.

Why it matters

CVE-2026-50167 is a vulnerability in Kurrier that could allow an attacker to read and enumerate resources belonging to another account. Defenders should prioritize verifying their Kurrier installations, reviewing API key management, and monitoring for suspicious activity.

  • An attacker could read and enumerate webhook and identity resources belonging to another account.
  • Defenders need to verify their Kurrier installations and ensure they are running version 1.2.4 or later.
  • Defenders should review their API key management and monitor for suspicious activity.

Technical summary

The Kurrier API did not enforce ownership checks for authenticated requests when listing and retrieving webhook and identity resources. This could allow an attacker with a valid API key to read and enumerate resources belonging to another account. The vulnerability is fixed in version 1.2.4. Affected product deployments should be verified, and API key management should be reviewed to ensure proper ownership checks are in place. Defenders should also monitor for suspicious activity and implement additional security measures as needed to prevent exploitation.

Defensive priority

Defenders should prioritize verifying their Kurrier installations and ensuring they are running version 1.2.4 or later. They should also review their API key management and monitor for any suspicious activity.

Recommended defensive actions

  • Verify Kurrier installation version and upgrade to 1.2.4 or later if necessary
  • Review API key management and ensure proper ownership checks are in place
  • Monitor for suspicious activity and implement additional security measures as needed
  • Perform a thorough review of webhook and identity resources to identify potential exposure
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up

Evidence notes

The CVE record and NVD entry provide details on the vulnerability, including its description, CVSS score, and affected versions. The GitHub commit, pull request, and release tag provide additional context on the fix.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-50167 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-50167

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-50167 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-50167

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.