CVE-2026-50167

Source
https://cve.org/CVERecord?id=CVE-2026-50167
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-50167.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-50167
Aliases
  • GHSA-f7h3-f5vh-3764
Published
2026-08-18T18:01:08Z
Modified
2026-08-21T03:30:30Z
Severity
  • 5.3 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
Kurrier: Authenticated cross-user authorization bypass in Kurrier API
Details

Kurrier is a modern, self-hosted workspace for email, calendar, contacts, and storage. Prior to 1.2.4, Kurrier API endpoints for listing and retrieving webhook and identity resources did not enforce ownership checks for authenticated API requests. An attacker with a valid API key could use another account's identifiers to read and enumerate webhook and identity resources belonging to that account through apps/worker/server/routes/api/kurrier/webhooks/[id].get.ts, apps/worker/server/routes/api/kurrier/webhooks/index.get.ts, apps/worker/server/routes/api/kurrier/identities/[id].get.ts, and apps/worker/server/routes/api/kurrier/identities/index.get.ts. Anonymous requests and invalid API keys were rejected, and cross-user modification operations were blocked, but affected GET and list operations could expose another user's resource metadata. This issue is fixed in version 1.2.4.

Database specific
{
    "cna_assigner": "GitHub_M",
    "cwe_ids": [
        "CWE-639"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/50xxx/CVE-2026-50167.json"
}
References

Affected packages

Git / github.com/kurrier-org/kurrier

Affected ranges

Type
GIT
Repo
https://github.com/kurrier-org/kurrier
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Fixed
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "1.2.4"
        }
    ],
    "source": [
        "AFFECTED_FIELD",
        "REFERENCES"
    ]
}

Affected versions

Other
v
v0.*
v0.0.10
v0.0.100
v0.0.101
v0.0.11
v0.0.12
v0.0.13
v0.0.14
v0.0.15
v0.0.16
v0.0.17
v0.0.18
v0.0.19
v0.0.20
v0.0.21
v0.0.22
v0.0.23
v0.0.24
v0.0.25
v0.0.26
v0.0.27
v0.0.28
v0.0.30
v0.0.31
v0.0.32
v0.0.33
v0.0.34
v0.0.35
v0.0.36
v0.0.37
v0.0.38
v0.0.39
v0.0.40
v0.0.41
v0.0.42
v0.0.43
v0.0.44
v0.0.45
v0.0.46
v0.0.47
v0.0.48
v0.0.49
v0.0.5
v0.0.50
v0.0.51
v0.0.52
v0.0.53
v0.0.54
v0.0.55
v0.0.58
v0.0.59
v0.0.60
v0.0.61
v0.0.63
v0.0.64
v0.0.65
v0.0.66
v0.0.68
v0.0.69
v0.0.70
v0.0.71
v0.0.72
v0.0.73
v0.0.74
v0.0.75
v0.0.76
v0.0.77
v0.0.78
v0.0.80
v0.0.85
v0.0.86
v0.0.90
v0.0.91
v0.0.94
v0.0.97
v0.0.98
v1.*
v1.0.2
v1.0.3
v1.0.4
v1.1.1
v1.1.12
v1.1.2
v1.1.3
v1.1.4
v1.1.5
v1.1.7
v1.1.8
v1.1.9
v1.2.3

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-50167.json"