Rescana
Critical Vulnerabilities in Kaltura HTML5 Player Expose Organizations to Attacks
Article Content
Two critical vulnerabilities, CVE-2026-19912 and CVE-2026-19913, have been discovered in the Kaltura HTML5 Player Library (mwEmbed/html5lib). These flaws allow unauthenticated remote attackers to execute arbitrary code and read sensitive files on affected servers. The vulnerabilities stem from unsafe deserialization and improper handling of user-controlled parameters in the mwEmbedLoader.php endpoint. Over 600 internet-facing instances are at risk, including those hosted on Kaltura's multi-tenant CDN infrastructure. As of now, no official patches are available, and organizations are advised to restrict access to the vulnerable endpoint. The vulnerabilities have received CVSS scores in the critical range (9.1-10.0), indicating a severe risk to affected systems. Exploitation methods are straightforward, with proof-of-concept code available for both vulnerabilities. The affected versions include html5lib v2.45, v2.103, and earlier releases.
Key Points: • Two critical vulnerabilities in Kaltura HTML5 Player allow remote code execution and file read. • Over 600 instances are exposed, with no patches currently available. • Attackers can exploit these vulnerabilities without authentication, posing a significant risk.
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.