<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Unpatched Kaltura mwEmbed Flaws Could Let Remote Attackers Read Files and Run Code]]></title><description><![CDATA[<p dir="auto">Two unpatched vulnerabilities have been disclosed in Kaltura's HTML5 video player library, potentially allowing a remote, unauthenticated attacker to read arbitrary files from a server and execute code on it. The issues were reported by the CERT Coordination Center (CERT/CC) and both stem from the same unsafe deserialization flaw located in the <code>mwEmbedLoader.php</code> endpoint of the mwEmbed player. Because the flaws remain unpatched, there is currently no official fix available for affected deployments.</p>
<ul>
<li><strong><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-19913" target="_blank" rel="noopener noreferrer nofollow ugc">CVE-2026-19913</a></strong> – Allows arbitrary file read on the server.</li>
<li><strong><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-19912" target="_blank" rel="noopener noreferrer nofollow ugc">CVE-2026-19912</a></strong> – Allows remote code execution via the same vulnerable deserialization path.</li>
</ul>
<p dir="auto">Both vulnerabilities share a root cause, meaning a single successful exploit chain could potentially escalate from file disclosure to full code execution, depending on server configuration and the attacker's ability to reach the endpoint. The lack of a patch means administrators need to consider temporary mitigations, such as restricting access to the <code>mwEmbedLoader.php</code> endpoint via web application firewall rules or network-level controls, until an official update is released.</p>
<p dir="auto">The disclosure highlights a broader concern: third-party media libraries often run with elevated privileges on web servers, and a single unpatched component can undermine the entire hosting environment. It is advisable to audit any Kaltura-integrated systems for exposure to this endpoint and monitor for unusual requests targeting it.</p>
<p dir="auto">Source: <a href="https://thehackernews.com/2026/08/unpatched-kaltura-mwembed-flaws-could.html" target="_blank" rel="noopener noreferrer nofollow ugc">The Hacker News</a></p>
<p dir="auto">Is your organization currently running Kaltura's mwEmbed player, and if so, what temporary controls are you putting in place while waiting for an official patch?</p>
]]></description><link>https://xploitlk.com/topic/162/unpatched-kaltura-mwembed-flaws-could-let-remote-attackers-read-files-and-run-code</link><generator>RSS for Node</generator><lastBuildDate>Sat, 05 Sep 2026 13:29:09 GMT</lastBuildDate><atom:link href="https://xploitlk.com/topic/162.rss" rel="self" type="application/rss+xml"/><pubDate>Mon, 31 Aug 2026 04:30:26 GMT</pubDate><ttl>60</ttl></channel></rss>