Kaltura mwEmbedLoader unsafe deserialization flaws (multiple vulnerabilities)
Vulnerability
Summary
Hide ▲
Show ▼
CERT/CC disclosed two unpatched Kaltura mwEmbedLoader vulnerabilities, CVE-2026-19913 and CVE-2026-19912, that expose html5lib v2.45, v2.103 and earlier to remote unauthenticated file read and code execution risk. The flaws affect the mwEmbedLoader.php endpoint and can reach both customer installations and shared multi-tenant hosts. No patch is available, so administrators have to rely on access restriction and input hardening.
Related Happenings
Kaltura mwEmbedLoader.php access restrictions and ServiceUrl allow-list guidance
Advisory/Mitigation
H score43
First: 26.08.2026 14:55
Last: 26.08.2026 14:55
Sources 1
How related:
Administrators are advised to restrict or disable external access to the endpoint and to enforce a strict allow-list for the ServiceUrl parameter that permits only legitimate backend API URLs.
About this happening:
CERT/CC issued mitigation guidance for exposed Kaltura mwEmbedLoader.php deployments to reduce risk from the unpatched deserialization flaws. Administrators were told...
Kaltura mwEmbedLoader.php access restrictions and ServiceUrl allow-list guidance
Advisory/MitigationHow related: Administrators are advised to restrict or disable external access to the endpoint and to enforce a strict allow-list for the ServiceUrl parameter that permits only legitimate backend API URLs.
About this happening: CERT/CC issued mitigation guidance for exposed Kaltura mwEmbedLoader.php deployments to reduce risk from the unpatched deserialization flaws. Administrators were told...
Magento PolyShell mitigation guidance
Advisory/Mitigation
H score29
First: 20.03.2026 11:30
Last: 20.03.2026 11:30
Sources 1
About this happening:
Sansec issued mitigation guidance for Magento storefronts after identifying a critical REST API file-upload flaw that can enable remote code execution or acc...
Magento PolyShell mitigation guidance
Advisory/MitigationAbout this happening: Sansec issued mitigation guidance for Magento storefronts after identifying a critical REST API file-upload flaw that can enable remote code execution or acc...
Timeline
-
26.08.2026 14:55 1 articles · 3h ago
Researcher reports Kaltura mwEmbedLoader flaws to a vendor security contact
Initial DisclosureA researcher first reported the Kaltura mwEmbedLoader unsafe deserialization flaws to a vendor security contact on March 23, 2026.
Show sources
- Unpatched Kaltura mwEmbed Flaws Could Let Remote Attackers Read Files and Run Code — thehackernews.com — 26.08.2026 14:55
-
26.08.2026 14:55 1 articles · 3h ago
Researcher resends the Kaltura flaw report from a corporate address
Untyped PhaseThe researcher resent the Kaltura flaw report from a corporate address on April 13, 2026.
Show sources
- Unpatched Kaltura mwEmbed Flaws Could Let Remote Attackers Read Files and Run Code — thehackernews.com — 26.08.2026 14:55
-
26.08.2026 14:55 1 articles · 3h ago
Researcher contacts Kaltura's CISO on LinkedIn about the mwEmbedLoader flaws
Untyped PhaseThe researcher contacted Kaltura's CISO on LinkedIn about the mwEmbedLoader flaws on May 23, 2026.
Show sources
- Unpatched Kaltura mwEmbed Flaws Could Let Remote Attackers Read Files and Run Code — thehackernews.com — 26.08.2026 14:55
-
26.08.2026 14:55 1 articles · 3h ago
Researcher escalates the Kaltura flaw report through a national CERT
Untyped PhaseThe researcher escalated the Kaltura case through a national CERT on July 2, 2026.
Show sources
- Unpatched Kaltura mwEmbed Flaws Could Let Remote Attackers Read Files and Run Code — thehackernews.com — 26.08.2026 14:55
-
26.08.2026 14:55 1 articles · 3h ago
CERT/CC notifies Kaltura about the two mwEmbedLoader vulnerabilities
Untyped PhaseCERT/CC notified Kaltura about both CVEs on July 8, 2026, and the vendor's status for the flaws remained Unknown with no statement received.
Show sources
- Unpatched Kaltura mwEmbed Flaws Could Let Remote Attackers Read Files and Run Code — thehackernews.com — 26.08.2026 14:55
-
26.08.2026 14:55 2 articles · 3h ago
CERT/CC discloses unpatched Kaltura mwEmbedLoader file-read and code-execution flaws
Technical Analysis UpdateCERT/CC disclosed two unpatched Kaltura HTML5 video player vulnerabilities, CVE-2026-19913 and CVE-2026-19912, that let a remote, unauthenticated attacker read arbitrary files from a server and execute code through unsafe deserialization in mwEmbedLoader.php. The note said the vulnerable endpoint is exposed on customer installations and shared multi-tenant CDN infrastructure.
Show sources
- Unpatched Kaltura mwEmbed Flaws Could Let Remote Attackers Read Files and Run Code — thehackernews.com — 26.08.2026 14:55
- Unpatched Kaltura mwEmbed Flaws Could Let Remote Attackers Read Files and Run Code — thehackernews.com — 26.08.2026 14:55