Skip to main content
EPSS 0.5%top 57%

VU#308749: Remote Code Execution and Arbitrary File Read Vulnerabilities in Kaltura Servers

0
Critical
Published: 08/25/2026 (08/25/2026, 16:21:05 UTC)
Source: CERT/CC

Description

The Kaltura HTML5 Player Library (mwEmbed / html5lib) versions v2.45, v2.103, and earlier v2.x releases contain two vulnerabilities involving insecure deserialization. These flaws allow remote, unauthenticated attackers to read arbitrary local files and execute arbitrary code as the web-server user via the vulnerable mwEmbedLoader.php endpoint. The vulnerabilities stem from unsafe deserialization of user-controlled input and insufficient sanitization of a path parameter, enabling directory traversal and remote code execution. These issues affect legacy Player V2 versions but not the currently supported Player V7. Until patches are applied, restricting or disabling access to the vulnerable endpoint is advised.

Affected software

Affected versions
<=2.45<=2.103

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/10/2026, 03:52:26 UTC

Technical Analysis

Kaltura's HTML5 Player Library exposes the mwEmbedLoader.php endpoint which accepts a user-controlled ServiceUrl parameter. The KalturaClientBase PHP client library fetches data from this URL and unserializes it without validation, leading to CVE-2026-19913 where an attacker can read arbitrary files by supplying a file:// URL and triggering error messages that leak file contents. CVE-2026-19912 arises from unsanitized uiconf_id parameter used in file path construction, allowing directory traversal to write malicious serialized PHP objects to web-accessible directories, enabling remote code execution. These vulnerabilities require no authentication and affect all deployments exposing the vulnerable endpoint, including Kaltura's shared multi-tenant CDN infrastructure. The vulnerabilities are limited to legacy Player V2 versions; Player V7 is not affected.

Potential Impact

Remote, unauthenticated attackers can read arbitrary local files, potentially exposing sensitive data such as database credentials and API keys (CVE-2026-19913). They can also achieve remote code execution as the web-server user (CVE-2026-19912), allowing modification or exfiltration of platform data, deployment of persistence tools, and further compromise. The vulnerabilities affect not only individual customer installations but also tenants on Kaltura's shared CDN infrastructure, increasing the scope of impact.

Mitigation Recommendations

Kaltura has released patches for all affected legacy Player V2 versions. Users should update to these patched versions or migrate to the supported Kaltura Player V7 platform. Until patches are applied, it is recommended to restrict or disable external access to the mwEmbedLoader.php endpoint and enforce a strict allow-list for the ServiceUrl parameter to permit only legitimate backend API URLs. These mitigations reduce risk by limiting exposure to the vulnerable functionality.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Classification
{"confidence":0.95,"severitySource":"heuristic","classifier":"rss-v2"}
Article Source
{"url":"https://kb.cert.org/vuls/id/308749","fetched":true,"fetchedAt":"2026-08-25T16:20:37.001Z","wordCount":730}

Threat ID: 6a8dc0d5acd9273b496c7f59

Added to database: 08/25/2026, 16:20:37 UTC

Last enriched: 09/10/2026, 03:52:26 UTC

Last updated: 10/08/2026, 18:48:43 UTC

Views: 91

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses