← All articles

Unpatched Kaltura video player flaws allow unauthenticated file read and code execution

CERT/CC disclosed two unpatched flaws in Kaltura's HTML5 video player library that let a remote, unauthenticated attacker read files from a server and run code, with only network access to the endpoint required. Both stem from the same unsafe deserialization in the mwEmbedLoader.php endpoint, which takes a user-controlled ServiceUrl parameter and passes fetched data to PHP's unserialize without validating it. Supplying a file path lets an attacker read any file the web server can access, including credentials and API keys, while the deserialization also enables code execution. CERT/CC could not reach the vendor, and because the endpoint is exposed on Kaltura's shared multi-tenant infrastructure, the flaws can affect many tenants at once.

Check
Since there is no vendor patch, restrict or disable external access to the mwEmbedLoader.php endpoint and enforce a strict allow-list for the ServiceUrl parameter permitting only known backend API URLs.
Affected
Organizations running the Kaltura HTML5 player library exposing mwEmbedLoader.php (CVE-2026-19913, CVE-2026-19912); an unauthenticated attacker can read sensitive files and execute code, with shared-CDN exposure widening the impact.
Fix
Block or lock down the vulnerable endpoint, allow-list ServiceUrl values, monitor for suspicious file-read attempts, rotate any secrets that may have been exposed, and watch for a vendor fix.