CVE Tools

Unpatched Kaltura mwEmbed Flaws Could Let Remote Attackers Read Files and Run Code

The Hacker NewsBy The Hacker News

PoC publicmwEmbedhtml5lib

Our summary

CERT/CC has disclosed two critical, unpatched vulnerabilities in the Kaltura mwEmbed player library, specifically affecting html5lib versions v2.45 and v2.103 and earlier. The flaws, identified as CVE-2026-19913 and CVE-2026-19912, originate from unsafe deserialization in the mwEmbedLoader.php endpoint, allowing unauthenticated remote attackers to read arbitrary files and execute code without requiring a valid session token. Although no official patch is currently available because the vendor could not be reached, administrators are advised to immediately restrict external access to the endpoint and enforce strict allow-lists for the ServiceUrl parameter to mitigate these risks.

Read at The Hacker News

The Hacker News publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store