PT-2026-77266 · Kurrier · Kurrier

CVE-2026-50167

·

Published

2026-08-18

·

Updated

2026-08-18

CVSS v4.0

5.3

Medium

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions Kurrier versions prior to 1.2.4
Description Authenticated API requests for listing and retrieving webhook and identity resources do not enforce ownership checks. An attacker with a valid API key can use identifiers from another account to read and enumerate resource metadata. This occurs through the following API endpoints:
  • '/api/kurrier/webhooks/[id]'
  • '/api/kurrier/webhooks/'
  • '/api/kurrier/identities/[id]'
  • '/api/kurrier/identities/'
Recommendations Update to version 1.2.4.

Exploit

Fix

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-50167
GHSA-F7H3-F5VH-3764

Affected Products

Kurrier