Critical Vulnerabilities in Kaltura HTML5 Player Expose Organizations to Attacks

Critical Vulnerabilities in Kaltura HTML5 Player Expose Organizations to Attacks

First seen 26 Aug 2026, 15:18 UTC Kb.CertRescanawww.rapid7.comnvd.nist.govwww.cve.org 72.8

Article Content

Browse articles
ThreatCluster

Two critical vulnerabilities, CVE-2026-19912 and CVE-2026-19913, have been discovered in the Kaltura HTML5 Player Library (mwEmbed/html5lib). These flaws allow unauthenticated remote attackers to execute arbitrary code and read sensitive files on affected servers. The vulnerabilities stem from unsafe deserialization and improper handling of user-controlled parameters in the mwEmbedLoader.php endpoint. Over 600 internet-facing instances are at risk, including those hosted on Kaltura's multi-tenant CDN infrastructure. As of now, no official patches are available, and organizations are advised to restrict access to the vulnerable endpoint. The vulnerabilities have received CVSS scores in the critical range (9.1-10.0), indicating a severe risk to affected systems. Exploitation methods are straightforward, with proof-of-concept code available for both vulnerabilities. The affected versions include html5lib v2.45, v2.103, and earlier releases.

Key Points: • Two critical vulnerabilities in Kaltura HTML5 Player allow remote code execution and file read. • Over 600 instances are exposed, with no patches currently available. • Attackers can exploit these vulnerabilities without authentication, posing a significant risk.

Timeline

2026-08-25
CVE-2026-19912 and CVE-2026-19913 published
Kaltura HTML5 Player vulnerabilities disclosed, allowing remote code execution and file read.
Kb.Cert
2026-08-26
Critical vulnerabilities reported in Kaltura
Rescana reports on two critical vulnerabilities affecting Kaltura's HTML5 Player, with significant implications for organizations.
Rescana
2026-08-26
NVD CVE records published
NVD includes CVE-2026-19913 in its database, confirming the vulnerability details.
nvd.nist.gov
2026-08-26
Rapid7 CVE-2026-19912 report
Rapid7 provides additional details on the remote code execution vulnerability in Kaltura's HTML5 player.
Rapid7