CVE-2026-19912: CWE-20 Improper Input Validation in Kaltura Kaltura HTML5 Video Player, html5 library
Description
The Kaltura HTML5 player (mwEmbed / html5lib) contains an unauthenticated remote code execution vulnerability caused by unsafe data deserialization and unsanitized filesystem path construction. mwEmbedLoader.php accepts a user‑controlled ServiceUrl, whose response is passed to unserialize(), and the resulting object’s fields are written to a cache path derived from attacker‑supplied uiconf_id without proper path validation. An attacker can write arbitrary files into web‑accessible locations and achieve code execution as the webserver user. Affected versions include html5lib v2.45, v2.103 and earlier, and other v2.x releases exposing the vulnerable endpoint.
CVSS v3.1
Score 9.8critical
Affected software
Kaltura
Kaltura HTML5 Video Player, html5 library
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The Kaltura HTML5 player (mwEmbed / html5lib) contains an unauthenticated remote code execution vulnerability due to unsafe data deserialization and unsanitized filesystem path construction. Specifically, mwEmbedLoader.php accepts a user-controlled ServiceUrl, whose response is passed to PHP's unserialize() function. The resulting object's fields are used to construct a cache path derived from an attacker-supplied uiconf_id without proper path validation. This allows an attacker to write arbitrary files into web-accessible locations and achieve code execution with the privileges of the webserver user. Affected versions include html5lib v2.45, v2.103, and other v2.x releases exposing the vulnerable endpoint. There is no vendor advisory indicating a patch or fix at this time.
Potential Impact
Successful exploitation allows unauthenticated remote attackers to execute arbitrary code on the server running the Kaltura HTML5 Video Player by writing malicious files to web-accessible locations. This can lead to full compromise of the webserver process, resulting in confidentiality, integrity, and availability impacts. The CVSS score of 9.8 reflects the critical severity and ease of exploitation without authentication.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory at https://kb.cert.org/vuls/id/308749 for current remediation guidance. Until an official fix is available, restrict access to the vulnerable endpoint if possible and monitor for suspicious activity related to file writes or unserialize() usage. Avoid exposing the vulnerable service publicly if feasible.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- certcc
- Date Reserved
- 2026-08-14T20:07:50.299Z
- State
- PUBLISHED
- Vendor Advisory Urls
- [{"url":"https://kb.cert.org/vuls/id/308749","vendor":"CERT"}]
Threat ID: 6a8dc505acd9273b4972ab48
Added to database: 08/25/2026, 16:38:29 UTC
Last enriched: 09/07/2026, 14:25:53 UTC
Last updated: 10/09/2026, 18:48:18 UTC
Views: 51
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.