VU#308749: Remote Code Execution and Arbitrary File Read Vulnerabilities in Kaltura Servers
Description
The Kaltura HTML5 Player Library (mwEmbed / html5lib) versions v2.45, v2.103, and earlier v2.x releases contain two vulnerabilities involving insecure deserialization. These flaws allow remote, unauthenticated attackers to read arbitrary local files and execute arbitrary code as the web-server user via the vulnerable mwEmbedLoader.php endpoint. The vulnerabilities stem from unsafe deserialization of user-controlled input and insufficient sanitization of a path parameter, enabling directory traversal and remote code execution. These issues affect legacy Player V2 versions but not the currently supported Player V7. Until patches are applied, restricting or disabling access to the vulnerable endpoint is advised.
Affected software
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Kaltura's HTML5 Player Library exposes the mwEmbedLoader.php endpoint which accepts a user-controlled ServiceUrl parameter. The KalturaClientBase PHP client library fetches data from this URL and unserializes it without validation, leading to CVE-2026-19913 where an attacker can read arbitrary files by supplying a file:// URL and triggering error messages that leak file contents. CVE-2026-19912 arises from unsanitized uiconf_id parameter used in file path construction, allowing directory traversal to write malicious serialized PHP objects to web-accessible directories, enabling remote code execution. These vulnerabilities require no authentication and affect all deployments exposing the vulnerable endpoint, including Kaltura's shared multi-tenant CDN infrastructure. The vulnerabilities are limited to legacy Player V2 versions; Player V7 is not affected.
Potential Impact
Remote, unauthenticated attackers can read arbitrary local files, potentially exposing sensitive data such as database credentials and API keys (CVE-2026-19913). They can also achieve remote code execution as the web-server user (CVE-2026-19912), allowing modification or exfiltration of platform data, deployment of persistence tools, and further compromise. The vulnerabilities affect not only individual customer installations but also tenants on Kaltura's shared CDN infrastructure, increasing the scope of impact.
Mitigation Recommendations
Kaltura has released patches for all affected legacy Player V2 versions. Users should update to these patched versions or migrate to the supported Kaltura Player V7 platform. Until patches are applied, it is recommended to restrict or disable external access to the mwEmbedLoader.php endpoint and enforce a strict allow-list for the ServiceUrl parameter to permit only legitimate backend API URLs. These mitigations reduce risk by limiting exposure to the vulnerable functionality.
Technical Details
- Classification
- {"confidence":0.95,"severitySource":"heuristic","classifier":"rss-v2"}
- Article Source
- {"url":"https://kb.cert.org/vuls/id/308749","fetched":true,"fetchedAt":"2026-08-25T16:20:37.001Z","wordCount":730}
Threat ID: 6a8dc0d5acd9273b496c7f59
Added to database: 08/25/2026, 16:20:37 UTC
Last enriched: 09/10/2026, 03:52:26 UTC
Last updated: 10/08/2026, 18:48:43 UTC
Views: 91
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.