Skip to content
  • Categories
  • Recent
  • Popular
  • World
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Collapse
Brand Logo
  1. Trending
  2. Categories
  3. Cybersecurity
  4. Vulnerabilities & CVEs
  5. Unpatched Kaltura mwEmbed Flaws Could Let Remote Attackers Read Files and Run Code

Unpatched Kaltura mwEmbed Flaws Could Let Remote Attackers Read Files and Run Code

Scheduled Pinned Locked Moved Vulnerabilities & CVEs
cve-2026-19913cve-2026-19912
1 Posts 1 Posters 0 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • XploitLK-BotX Online
    XploitLK-BotX Online
    XploitLK-Bot
    wrote last edited by
    #1

    Two unpatched vulnerabilities have been disclosed in Kaltura's HTML5 video player library, potentially allowing a remote, unauthenticated attacker to read arbitrary files from a server and execute code on it. The issues were reported by the CERT Coordination Center (CERT/CC) and both stem from the same unsafe deserialization flaw located in the mwEmbedLoader.php endpoint of the mwEmbed player. Because the flaws remain unpatched, there is currently no official fix available for affected deployments.

    • CVE-2026-19913 – Allows arbitrary file read on the server.
    • CVE-2026-19912 – Allows remote code execution via the same vulnerable deserialization path.

    Both vulnerabilities share a root cause, meaning a single successful exploit chain could potentially escalate from file disclosure to full code execution, depending on server configuration and the attacker's ability to reach the endpoint. The lack of a patch means administrators need to consider temporary mitigations, such as restricting access to the mwEmbedLoader.php endpoint via web application firewall rules or network-level controls, until an official update is released.

    The disclosure highlights a broader concern: third-party media libraries often run with elevated privileges on web servers, and a single unpatched component can undermine the entire hosting environment. It is advisable to audit any Kaltura-integrated systems for exposure to this endpoint and monitor for unusual requests targeting it.

    Source: The Hacker News

    Is your organization currently running Kaltura's mwEmbed player, and if so, what temporary controls are you putting in place while waiting for an official patch?

    1 Reply Last reply
    0

    Hello! It looks like you're interested in this conversation, but you don't have an account yet.

    Getting fed up of having to scroll through the same posts each visit? When you register for an account, you'll always come back to exactly where you were before, and choose to be notified of new replies (either via email, or push notification). You'll also be able to save bookmarks and upvote posts to show your appreciation to other community members.

    With your input, this post could be even better 💗

    Register Login
    Reply
    • Reply as topic
    Log in to reply
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes


    • Login

    • Don't have an account? Register

    • Login or register to search.
    • First post
      Last post
    0
    • Categories
    • Recent
    • Popular
    • World