VU#308749: Remote Code Execution and Arbitrary File Read Vulnerabilities in Kaltura Servers

Date Aug 25, 2026
Type Coordinated disclosure
Signal Patch review
Vendor / Product Kaltura · Servers
Patch review

Summary

Overview The Kaltura HTML5 Player Library (mwEmbed / html5lib) contains two vulnerabilities, both involving the same insecure deserialization flaw, that enable arbitrary file read and remote code execution. Affected versions include html5lib v2.45, v2.103 and earlier, and other v2.x releases that expose the vulnerable mwEmbedLoader.php endpoint. Until a vendor patch is available, users are advised to restrict access to the affected endpoint or disable it entirely. Description Kaltura is an AI video platform that provides tools for video management, publishing, playback, and integration with web applications. Kaltura’s HTML5 player library exposes the mwEmbedLoader.php endpoint, which accepts a user-controlled ServiceUrl parameter as the target URL for backend API requests. The KalturaClientBase PHP client library fetches data from this... Related CVEs: CVE-2026-19912, CVE-2026-19913.

Why it matters

CERT/CC notes often cover coordinated disclosures, multi-vendor exposure, infrastructure risk, or cases where remediation guidance is still developing.

Operator check

Review the CERT/CC Vulnerability Note and compare the affected vendor and product list against your inventory. Apply vendor fixes or compensating controls for Servers where available.

Sources

PatchBrief uses public sources. It does not scan environments, verify exposure, or replace vendor guidance.