MEDIUM
kerberos-io
CVE published 2026-08-20
CVE-2026-50192
The Kerberos Agent, a video surveillance management agent, contains a vulnerability prior to version 3.6.26. This vulnerability involves the Kerberos Hub upload path, which sends the agent's Hub credentials in custom request headers to an operator-configured Hub URL. Due to the lack of a CheckRedirect policy in the HTTP client used for the upload process, these credentials can be inadvertently forwarded t [truncated]