Unpatched Kaltura mwEmbed Flaws Could Let Remote Attackers Read Files and Run Code
Overview
Researchers at the CERT Coordination Center have identified two serious vulnerabilities in Kaltura's HTML5 video player library. These flaws, tracked as CVE-2026-19913 and CVE-2026-19912, allow remote, unauthenticated attackers to read arbitrary files from a server and execute malicious code. Both vulnerabilities stem from unsafe deserialization within the mwEmbedLoader.php endpoint of the mwEmbed player. This poses a significant risk for any organization using Kaltura's video services, as attackers could exploit these weaknesses to gain unauthorized access to sensitive data or disrupt operations. As of now, there are no known patches or fixes available for these vulnerabilities, making it crucial for affected users to take immediate action to protect their systems.
Key Takeaways
- Affected Systems: Kaltura's HTML5 video player library, mwEmbed player
- Action Required: Organizations using Kaltura's video services should implement security measures such as restricting access to the affected endpoint and monitoring for unusual activity while waiting for an official patch.
- Timeline: Newly disclosed
Original Article Summary
The CERT Coordination Center (CERT/CC) has disclosed two unpatched vulnerabilities in Kaltura's HTML5 video player library that allow a remote, unauthenticated attacker to read arbitrary files from a server and execute code on it. The flaws, tracked as CVE-2026-19913 and CVE-2026-19912, both stem from the same unsafe deserialization in the mwEmbedLoader.php endpoint of the mwEmbed player
Impact
Kaltura's HTML5 video player library, mwEmbed player
Exploitation Status
The exploitation status is currently unknown. Monitor vendor advisories and security bulletins for updates.
Timeline
Newly disclosed
Remediation
Organizations using Kaltura's video services should implement security measures such as restricting access to the affected endpoint and monitoring for unusual activity while waiting for an official patch. Regular updates and security audits are also recommended.
Additional Information
This threat intelligence is aggregated from trusted cybersecurity sources. For the most up-to-date information, technical details, and official vendor guidance, please refer to the original article linked below.
Related Topics: This incident relates to CVE, Exploit, Vulnerability.