PatchSiren

kerberos-io CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM kerberos-io CVE published 2026-08-20

CVE-2026-50192

The Kerberos Agent, a video surveillance management agent, contains a vulnerability prior to version 3.6.26. This vulnerability involves the Kerberos Hub upload path, which sends the agent's Hub credentials in custom request headers to an operator-configured Hub URL. Due to the lack of a CheckRedirect policy in the HTTP client used for the upload process, these credentials can be inadvertently forwarded t [truncated]