MEDIUM
kurrier-org
CVE published 2026-08-18
CVE-2026-50167
CVE-2026-50167 is a vulnerability in Kurrier, a self-hosted workspace for email, calendar, contacts, and storage. Prior to version 1.2.4, the Kurrier API did not enforce ownership checks for authenticated requests when listing and retrieving webhook and identity resources. This could allow an attacker with a valid API key to read and enumerate resources belonging to another account.