importantSYS.SOURCE: The Hacker News• 2026-08-26T17:25:00+05:30
Unpatched Kaltura mwEmbed Vulnerabilities Allow Remote Code Execution and File Disclosure
Two unpatched vulnerabilities in Kaltura's mwEmbed library allow remote attackers to read files and execute code via unsafe deserialization. Administrators are advised to restrict access and mitigate risks due to the lack of available patches.
The CERT Coordination Center (CERT/CC) has disclosed two unpatched vulnerabilities in Kaltura's HTML5 video player library that allow a remote, unauthenticated attacker to read arbitrary files from a server and execute code on it.
The flaws, tracked as CVE-2026-19913 and CVE-2026-19912, both stem from the same unsafe deserialization in the mwEmbedLoader.php endpoint of the mwEmbed player
*** END OF TRANSMISSION ***