CVE-2026-19912Disclosure

LOWCVSS 9.8 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts

Recommended action window: High priority (within 72h)

NVD description

The Kaltura HTML5 player (mwEmbed / html5lib) contains an unauthenticated remote code execution vulnerability caused by unsafe data deserialization and unsanitized filesystem path construction. mwEmbedLoader.php accepts a user‑controlled ServiceUrl, whose response is passed to unserialize(), and the resulting object’s fields are written to a cache path derived from attacker‑supplied uiconf_id without proper path validation. An attacker can write arbitrary files into web‑accessible locations and achieve code execution as the webserver user. Affected versions include html5lib v2.45, v2.103 and earlier, and other v2.x releases exposing the vulnerable endpoint.

2.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-20CWE-22

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Exploit tooling references are present in monitored signal
  • Patch or workaround signal is available
  • 6 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 1 signal
  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 6 signals
  • Disclosure: 3 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 4 mentions (2026-08-26); latest day: 1
  • 6 total mentions across 3 days

Deep dive

Activity timeline6 mentions / 3d
01234Mentions · 2026-08-25: 1Mentions · 2026-08-26: 4Mentions · 2026-08-27: 1Exploit Tool / Code · 2026-08-26: 1Patch / Workaround · 2026-08-25: 1Patch / Workaround · 2026-08-26: 2Technical Details · 2026-08-25: 1Technical Details · 2026-08-26: 4Technical Details · 2026-08-27: 108-2508-2608-27
Signal classification3 categories
Disclosure
350.0%
Patch
233.3%
General
116.7%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-08-251
Disclosure1
2026-08-264
Disclosure1General1Patch2
2026-08-271
Disclosure1
Full discourse6 posts
  • Rahmi Demir ⭐⭐⭐⭐⭐@rahmid3mir
    Patch

    🔴 Kaltura'da Yamasız Açık: Kimlik Doğrulamasız RCE Riski #Kaltura'nın HTML5 video oynatıcı kütüphanesinde, kimlik doğrulaması gerektirmeden uzaktan istismar edilebilen iki ciddi güvenlik açığı tespit edildi. #VestraDAO #Brolyz #Orta #Gibi CVE-2026-19913, saldırganların sunucudaki dosyaları okumasına; CVE-2026-19912 ise belirli koşullarda sunucu üzerinde uzaktan kod çalıştırmasına (RCE) olanak tanıyabiliyor. Açıkların temelinde mwEmbedLoader.php endpoint'inde bulunan güvensiz PHP deserialization işlemi bulunuyor. ⚠️ Daha da önemlisi: 🔴 Kimlik doğrulaması gerekmiyor 🔴 Ağ üzerinden erişim yeterli 🔴 Şu anda resmi bir yama bulunmuyor 🔴 Etkilenen endpoint Kaltura'nın paylaşımlı altyapısında da bulunabiliyor CERT/CC, yama yayınlanana kadar mwEmbedLoader.php endpoint'ine dış erişimin kısıtlanmasını veya tamamen kapatılmasını ve ServiceUrl parametresinin yalnızca güvenilir backend adreslerini kabul edecek şekilde sınırlandırılmasını öneriyor. Ayrıca endpoint'in erişilebilir olduğu sistemlerde veritabanı parolaları, yönetici bilgileri, API anahtarları ve diğer gizli bilgilerin döndürülmesi gerekebilir. Şu ana kadar bu açıkların gerçek saldırılarda kullanıldığına dair bir kanıt bildirilmiş değil. Ancak yama bulunmaması ve uzaktan kod çalıştırma ihtimali nedeniyle kurumların hemen önlem alması gerekiyor. Video oynatıcı #gibi görünen bir bileşen, sunucunun tamamına açılan kapıya dönüşebilir. #CyberSecurity

    Post summary

    Turkish-language post discloses two unauthenticated RCE/file-read flaws in Kaltura's HTML5 player via insecure PHP deserialization; no official patch exists, CERT/CC recommends endpoint access restrictions as workaround; no in-the-wild exploitation evidence reported.

    0002028
    521 followersView on X
  • Daily CyberSecurity@Daily_CyberSec
    Disclosure

    Two unpatched Kaltura server flaws (CVE-2026-19912, CVE-2026-19913) allow attackers to execute code and read files. Learn how to mitigate these risks. #Kaltura #CyberSecurity #CVE202619912 #CVE202619913 #InfoSec https://securityonline.info/kaltura-server-flaws/

    Post summary

    The article announces two unpatched Kaltura server vulnerabilities that allow code execution and file reading, and directs readers to mitigation instructions.

    00020441
    13.0K followersView on X
  • yousukezan@yousukezan
    Disclosure

    CERT/CCは、KalturaのHTML5動画プレーヤーライブラリに、認証なしの遠隔攻撃者がサーバー上の任意ファイルを読み取り、コード実行にもつなげられる未修正の脆弱性2件「CVE-2026-19913」「CVE-2026-19912」を公開した。 両方ともmwEmbedLoader.phpで、ServiceUrlから取得した内容を検証せずPHPのunserialize()へ渡すことが原因だ。認証やKalturaのセッショントークンは不要で、エンドポイントへ到達できれば攻撃できる。 CVE-2026-19913ではServiceUrlにfile://を指定してローカルファイルを取得させ、デシリアライズ失敗時のエラーに生データを反映させることで任意ファイルを読み取れる。研究者はlocal.iniからDB接続情報や管理者パスワードを取得した。 CVE-2026-19912では悪意あるシリアライズ済みオブジェクトを取得させ、uiconf_idのパストラバーサルでWeb公開ディレクトリへPHPファイルを書き込み、Webサーバーユーザー権限で実行できる。CERT/CCはKalturaと連絡が取れず、修正版はないとしている。 https://thehackernews.com/2026/08/unpatched-kaltura-mwembed-flaws-could.html

    Post summary

    CERT/CC disclosed two unserialized input vulnerabilities in Kaltura’s mwEmbedLoader.php that allow unauthenticated file reading and code execution, with no patch available yet.

    000101.4K
    14.9K followersView on X
  • Alexius McMullin@McM1Alex
    Disclosure

    Kaltura HTML5 video player: two critical unpatched vulnerabilities (CVE-2026-19913, CVE-2026-19912). Unsafe deserialization in mwEmbedLoader.php. Widely deployed, no fix yet. CERT Coordination Center disclosed August 26. #Cybersecurity

    Post summary

    CERT announced two critical unpatched deserialization vulnerabilities in Kaltura's HTML5 video player, with no patch available yet.

    0000039
    12 followersView on X
  • Autumn Good@autumn_good_35
    General

    『an attacker only needs network access to the affected html5lib endpoint.』 CVE-2026-19912 CVE-2026-19913 VU#308749 - Remote Code Execution and Arbitrary File Read Vulnerabilities in Kaltura Servers https://www.kb.cert.org/vuls/id/308749

    Post summary

    The text highlights a remote vulnerability requiring only network access to an html5lib endpoint and references RCE and file read issues in Kaltura servers, but it lacks details on patches, PoC, or active exploitation.

    00000467
    7.0K followersView on X
  • The Daily Tech Feed@dailytechonx
    Patch

    Massive security alarm: Kaltura’s html5lib has two unpatched CVEs allowing remote file reads and full remote code execution. CVE-2026-19912 and CVE-2026-19913 exploit unsafe deserialization in mwEmbedLoader.php with no authentication needed. Every tenant on shared infrastructure might be impacted. Operators must block the endpoint, strictly allow-list ServiceUrl, sanitize uiconf_id, deny PHP execution in caches, and rotate exposed creds. Very high severity. #CyberSecurity #Kaltura #RCE #FileRead #PHP #Vulnerability https://thedailytechfeed.com/critical-unpatched-kaltura-mwembed-flaws-enable-remote-file-read-code-execution/

    Post summary

    The post highlights two unpatched Kaltura CVEs that allow remote file reads and RCE, details the technical nature of the flaw, and outlines immediate mitigation steps while urging operators to block the vulnerable endpoint.

    0000031
    663 followersView on X

Explore more