{"apiVersion":"1.0","identifier":"CVE-2026-50192","description":"Kerberos Agent is an open source video (surveillance) management agent. Prior to version 3.6.26, the Kerberos Hub upload path sends the agent-s Hub credentials in the custom `X-Kerberos-Hub-PrivateKey` and `X-Kerberos-Hub-PublicKey` request headers to the operator-configured Hub URL (`config.HubURI`). The HTTP client used (`&http.Client{}` in `UploadKerberosHub`) is constructed without a `CheckRedirect` policy, so it follows HTTP redirects automatically. Go-s `net/http` strips only sensitive headers (`Authorization`, `Cookie`, `WWW-Authenticate`) on a cross-host redirect; it does not strip custom headers such as `X-Kerberos-Hub-PrivateKey`. As a result, if the configured `HubURI` returns a cross-host 30x redirect, the Hub private key is forwarded verbatim to the redirect target, disclosing the credential to an unintended third party. Version 3.6.26 fixes the issue by implementing the `CheckRedirect` strip plus a cross-host regression test is provided to the maintainer through the advisory-s private temporary fork.","publishedAt":"2026-08-20T22:17:20","lastModifiedAt":"2026-08-21T15:16:41","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-50192","cvssScore":6.9,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","epssProbability":0.00249,"riskScore":0.71,"affectedProduct":"Kerberos Agent","affectedVersions":"<3.6.26","vulnerabilityType":"Library","operatingSystems":[],"links":{"self":"https://www.redsauce.net/api/cves/CVE-2026-50192","webPages":{"es":"https://www.redsauce.net/es/cves/CVE-2026-50192","en":"https://www.redsauce.net/en/cves/CVE-2026-50192","fr":"https://www.redsauce.net/fr/cves/CVE-2026-50192","pt":"https://www.redsauce.net/pt/cves/CVE-2026-50192","de":"https://www.redsauce.net/de/cves/CVE-2026-50192","sk":"https://www.redsauce.net/sk/cves/CVE-2026-50192","el":"https://www.redsauce.net/el/cves/CVE-2026-50192"},"source":"https://nvd.nist.gov/vuln/detail/CVE-2026-50192"}}