Unpatched Kaltura mwEmbed Flaws Could Let Remote Attackers Read Files and Run Code
Summary
The CERT Coordination Center (CERT/CC) has disclosed two unpatched vulnerabilities in Kaltura's HTML5 video player library that allow a remote, unauthenticated attacker to read arbitrary files from a server and execute code on it. The flaws, tracked as CVE-2026-19913 and CVE-2026-19912, both stem from the same unsafe deserialization in the mwEmbedLoader.php endpoint of the mwEmbed player
Lotu Radar provides attributed news summaries and links to the original publisher. Full reporting and copyright remain with the source.