PatchSiren

kurrier-org CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM kurrier-org CVE published 2026-08-18

CVE-2026-50167

CVE-2026-50167 is a vulnerability in Kurrier, a self-hosted workspace for email, calendar, contacts, and storage. Prior to version 1.2.4, the Kurrier API did not enforce ownership checks for authenticated requests when listing and retrieving webhook and identity resources. This could allow an attacker with a valid API key to read and enumerate resources belonging to another account.