Two unpatched flaws in Kaltura's video player let attackers read files and run code
CERT/CC has gone public with a pair of bugs in Kaltura's mwEmbed library. Both trace back to the same old web-security sin: trusting user-supplied serialized data.

Key points
- CERT/CC disclosed two unpatched vulnerabilities in Kaltura's HTML5 mwEmbed video player, tracked as CVE-2026-19912 and CVE-2026-19913.
- Both flaws let a remote attacker with no login read files from the server and run their own code on it.
- The root cause is unsafe deserialization in a single file, mwEmbedLoader.php.
- No patch is available at the time of publication, and Kaltura powers video on a long list of universities, broadcasters and enterprise sites.
The CERT Coordination Center, a US-based group that helps coordinate the public disclosure of software flaws, has gone public with two bugs in Kaltura's video player that don't yet have a fix.
Kaltura is the video engine sitting quietly behind a lot of the internet you already use: university lecture portals, corporate training sites, news video players. Its open-source HTML5 player is called mwEmbed. That's the piece with the problem.
The flaws are tracked as CVE-2026-19912 and CVE-2026-19913. The original report was published by The Hacker News.
What can an attacker actually do?
An attacker anywhere on the internet, with no account, can read files off the server running the player and run their own code on it. That's about as bad as a web bug gets.
Reading arbitrary files means the attacker can grab configuration files or private keys sitting on disk. Running code, in security jargon remote code execution, means they can install software on the server or pivot to other systems. Both bugs live in the same endpoint, a file called mwEmbedLoader.php. Hit that URL with the wrong kind of input and you're in.
How did the bug get there?
Both vulnerabilities come from unsafe deserialization: the code takes data sent by a stranger and unpacks it as if it were trusted.
Programs often turn complex data into a compact string so they can save or transmit it. Turning it back into a usable object is called deserialization. If the program will deserialize whatever a random visitor sends it, an attacker can craft a booby-trapped string that, when unpacked, executes commands. It's the PHP equivalent of a bug pattern that has haunted Java and .NET apps for more than a decade. We covered a similar deserialization flaw in AVEVA's industrial SCADA software on 13 August, where a patch was at least available. Here, there isn't one. Not novel. Just unpatched.
Is there a fix yet?
No. Kaltura hasn't shipped a patched version of mwEmbed, and CERT/CC's advisory lists no vendor-supplied mitigation.
| Detail | Value |
|---|---|
| Affected product | Kaltura HTML5 video player (mwEmbed) |
| Vulnerable file | mwEmbedLoader.php |
| CVE IDs | CVE-2026-19912, CVE-2026-19913 |
| Root cause | Unsafe PHP deserialization |
| Attacker needs an account? | No |
| Patch available? | Not at time of publication |
Administrators running self-hosted Kaltura installations should block outside access to mwEmbedLoader.php at the web server or firewall until a fix arrives. Sites using Kaltura's cloud service should ask their account contact whether the hosted player is affected.
Should ordinary viewers worry?
Probably not directly. These bugs put the servers hosting Kaltura at risk, not the laptops of people watching video on them. You can't catch this by clicking play on a lecture recording.
The knock-on risk is the usual one. If an employer's Kaltura server gets compromised, whatever account details or internal documents live near it could leak. An unexpected password-reset email from a Kaltura-powered site in the coming weeks deserves the same suspicion you'd give any other unsolicited message.



