CVE-2026-19913Patch

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

The Kaltura HTML5 player (mwEmbed / html5lib) contains a local file disclosure vulnerability due to improper validation of the ServiceUrl parameter in mwEmbedLoader.php. This parameter is used as the base URL for a backend request and accepts non‑HTTP schemes such as file://. When an exception or error occurs, the response is subsequently deserialized and its raw contents are reflected to the client in an error message; this enables an unauthenticated, remote attacker to read any arbitrary internal file reachable by the server. Affected versions include html5lib v2.45, v2.103 and earlier, and other v2.x releases exposing the vulnerable endpoint.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-20CWE-73

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 6 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 5 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 4 mentions (2026-08-26); latest day: 1
  • 6 total mentions across 3 days

Deep dive

Activity timeline6 mentions / 3d
01234Mentions · 2026-08-25: 1Mentions · 2026-08-26: 4Mentions · 2026-08-27: 1Patch / Workaround · 2026-08-25: 1Patch / Workaround · 2026-08-26: 2Technical Details · 2026-08-25: 1Technical Details · 2026-08-26: 3Technical Details · 2026-08-27: 108-2508-2608-27
Signal classification3 categories
Patch
350.0%
Disclosure
233.3%
General
116.7%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-08-251
Patch1
2026-08-264
Disclosure1General1Patch2
2026-08-271
Disclosure1
Full discourse6 posts
  • Rahmi Demir ⭐⭐⭐⭐⭐@rahmid3mir
    Patch

    🔴 Kaltura'da Yamasız Açık: Kimlik Doğrulamasız RCE Riski #Kaltura'nın HTML5 video oynatıcı kütüphanesinde, kimlik doğrulaması gerektirmeden uzaktan istismar edilebilen iki ciddi güvenlik açığı tespit edildi. #VestraDAO #Brolyz #Orta #Gibi CVE-2026-19913, saldırganların sunucudaki dosyaları okumasına; CVE-2026-19912 ise belirli koşullarda sunucu üzerinde uzaktan kod çalıştırmasına (RCE) olanak tanıyabiliyor. Açıkların temelinde mwEmbedLoader.php endpoint'inde bulunan güvensiz PHP deserialization işlemi bulunuyor. ⚠️ Daha da önemlisi: 🔴 Kimlik doğrulaması gerekmiyor 🔴 Ağ üzerinden erişim yeterli 🔴 Şu anda resmi bir yama bulunmuyor 🔴 Etkilenen endpoint Kaltura'nın paylaşımlı altyapısında da bulunabiliyor CERT/CC, yama yayınlanana kadar mwEmbedLoader.php endpoint'ine dış erişimin kısıtlanmasını veya tamamen kapatılmasını ve ServiceUrl parametresinin yalnızca güvenilir backend adreslerini kabul edecek şekilde sınırlandırılmasını öneriyor. Ayrıca endpoint'in erişilebilir olduğu sistemlerde veritabanı parolaları, yönetici bilgileri, API anahtarları ve diğer gizli bilgilerin döndürülmesi gerekebilir. Şu ana kadar bu açıkların gerçek saldırılarda kullanıldığına dair bir kanıt bildirilmiş değil. Ancak yama bulunmaması ve uzaktan kod çalıştırma ihtimali nedeniyle kurumların hemen önlem alması gerekiyor. Video oynatıcı #gibi görünen bir bileşen, sunucunun tamamına açılan kapıya dönüşebilir. #CyberSecurity

    Post summary

    The text discloses two unpatched critical Kaltura vulnerabilities (RCE and File Read) stemming from unauthenticated PHP deserialization, explicitly notes no active exploitation observed, and focuses on CERT/CC recommended workarounds (endpoint blocking, parameter restriction, secret rotation) as the primary actionable guidance.

    0002028
    521 followersView on X
  • Daily CyberSecurity@Daily_CyberSec
    Patch

    Two unpatched Kaltura server flaws (CVE-2026-19912, CVE-2026-19913) allow attackers to execute code and read files. Learn how to mitigate these risks. #Kaltura #CyberSecurity #CVE202619912 #CVE202619913 #InfoSec https://securityonline.info/kaltura-server-flaws/

    Post summary

    The post announces two unpatched Kaltura server vulnerabilities that enable code execution and file access, directing readers toward mitigation steps while providing no exploit code or evidence of active attacks.

    00020441
    13.0K followersView on X
  • yousukezan@yousukezan
    Disclosure

    CERT/CCは、KalturaのHTML5動画プレーヤーライブラリに、認証なしの遠隔攻撃者がサーバー上の任意ファイルを読み取り、コード実行にもつなげられる未修正の脆弱性2件「CVE-2026-19913」「CVE-2026-19912」を公開した。 両方ともmwEmbedLoader.phpで、ServiceUrlから取得した内容を検証せずPHPのunserialize()へ渡すことが原因だ。認証やKalturaのセッショントークンは不要で、エンドポイントへ到達できれば攻撃できる。 CVE-2026-19913ではServiceUrlにfile://を指定してローカルファイルを取得させ、デシリアライズ失敗時のエラーに生データを反映させることで任意ファイルを読み取れる。研究者はlocal.iniからDB接続情報や管理者パスワードを取得した。 CVE-2026-19912では悪意あるシリアライズ済みオブジェクトを取得させ、uiconf_idのパストラバーサルでWeb公開ディレクトリへPHPファイルを書き込み、Webサーバーユーザー権限で実行できる。CERT/CCはKalturaと連絡が取れず、修正版はないとしている。 https://thehackernews.com/2026/08/unpatched-kaltura-mwembed-flaws-could.html

    Post summary

    The text discloses two unpatched Kaltura HTML5 player vulnerabilities (CVE‑2026‑19913 and CVE‑2026‑19912) that let unauthenticated attackers read arbitrary files or write and execute PHP, with no patch or mitigation currently available.

    000101.4K
    14.9K followersView on X
  • Alexius McMullin@McM1Alex
    Disclosure

    Kaltura HTML5 video player: two critical unpatched vulnerabilities (CVE-2026-19913, CVE-2026-19912). Unsafe deserialization in mwEmbedLoader.php. Widely deployed, no fix yet. CERT Coordination Center disclosed August 26. #Cybersecurity

    Post summary

    Two critical CVEs (CVE-2026-19913 and CVE-2026-19912) affecting Kaltura's HTML5 video player were disclosed, involving unsafe deserialization in mwEmbedLoader.php, with no fix yet and no evidence of active exploitation.

    0000039
    12 followersView on X
  • Autumn Good@autumn_good_35
    General

    『an attacker only needs network access to the affected html5lib endpoint.』 CVE-2026-19912 CVE-2026-19913 VU#308749 - Remote Code Execution and Arbitrary File Read Vulnerabilities in Kaltura Servers https://www.kb.cert.org/vuls/id/308749

    Post summary

    The excerpt notes that an attacker only needs network access to a vulnerable html5lib endpoint; it provides no proof of concept, exploit code, patch, or evidence of active exploitation.

    00000467
    7.0K followersView on X
  • The Daily Tech Feed@dailytechonx
    Patch

    Massive security alarm: Kaltura’s html5lib has two unpatched CVEs allowing remote file reads and full remote code execution. CVE-2026-19912 and CVE-2026-19913 exploit unsafe deserialization in mwEmbedLoader.php with no authentication needed. Every tenant on shared infrastructure might be impacted. Operators must block the endpoint, strictly allow-list ServiceUrl, sanitize uiconf_id, deny PHP execution in caches, and rotate exposed creds. Very high severity. #CyberSecurity #Kaltura #RCE #FileRead #PHP #Vulnerability https://thedailytechfeed.com/critical-unpatched-kaltura-mwembed-flaws-enable-remote-file-read-code-execution/

    Post summary

    Kaltura’s mwEmbedLoader.php hosts two unpatched vulnerabilities (CVE‑2026‑19912/19913) that enable remote file reads and RCE; operators are advised to apply listed mitigations until a vendor patch arrives.

    0000031
    663 followersView on X

Explore more