AI Stories on SHORT INFO are generated & curated with AI
2 linked sources 26 Aug, 15:37

CERT/CC discloses two unpatched Kaltura video player flaws allowing unauthenticated file read and remote code execution

The CERT Coordination Center has disclosed two unpatched vulnerabilities in Kaltura $KLTR's widely used HTML5 video player library that let an unauthenticated attacker read server files or run their own code, with no vendor fix available. Per CERT/CC and The Hacker News.

The CERT Coordination Center (CERT/CC) disclosed two unpatched vulnerabilities, CVE-2026-19913 and CVE-2026-19912, in Kaltura $KLTR's HTML5 player library (mwEmbed/html5lib), both stemming from the same unsafe deserialization flaw in the mwEmbedLoader.php endpoint. Neither requires authentication: an attacker only needs network access to the endpoint. CVE-2026-19913 lets an attacker read arbitrary server files, including database credentials, admin passwords and API keys. CVE-2026-19912 can achieve remote code execution as the web-server user. Because the vulnerable endpoint is also exposed on Kaltura's shared, multi-tenant CDN infrastructure, the flaws can affect every tenant served by those shared hosts, not just individual installs. Researcher Gerjan Wemekamp first reported the issue to Kaltura in March 2026; CERT/CC notified the vendor on July 8, 2026, and says it was unable to reach Kaltura to coordinate a fix. No patch is available as of publication, and neither CVE appeared in CISA's Known Exploited Vulnerabilities catalog as of August 25, 2026. Sources: CERT Coordination Center (CERT/CC), The Hacker News.

#cyber
Published on