Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Kaltura Vulnerabilities Permit Remote File Access and Code Execution

Kaltura Vulnerabilities Permit Remote File Access and Code Execution

Posted on August 26, 2026 By CWS

The CERT Coordination Center (CERT/CC) has revealed two significant security vulnerabilities in Kaltura’s HTML5 video player library. These vulnerabilities allow remote attackers to access files and execute code on affected servers without authentication. These flaws, identified as CVE-2026-19913 and CVE-2026-19912, originate from insecure deserialization processes within the mwEmbedLoader.php endpoint, part of the mwEmbed player library distributed by Kaltura.

Vulnerability Details and Impact

The vulnerabilities do not require authentication or Kaltura session tokens, with network access to the endpoint being the only prerequisite for exploitation. CERT/CC has been unable to coordinate a response from Kaltura regarding these security issues. As a result, administrators are strongly advised to limit or disable external access to the affected endpoint and employ a restricted allow-list for the ServiceUrl parameter to ensure only valid backend API URLs are used.

As of August 25, 2026, there have been no reported exploitations of these vulnerabilities, and they are not listed in the Cybersecurity and Infrastructure Security Agency’s (CISA) Known Exploited Vulnerabilities catalog. Kaltura, a platform for video management and integration, exposes the vulnerable loader on both customer installations and its shared production hosts, impacting multiple users.

Technical Breakdown of the Flaws

The first vulnerability, CVE-2026-19913, is linked to the ServiceUrl parameter, which directs backend API requests. This parameter can be manipulated to fetch local files instead of API responses, leading to the reflection of file contents in error messages. Researcher Gerjan Wemekamp demonstrated an escalation by retrieving sensitive configuration files containing database connections and passwords.

The second flaw, CVE-2026-19912, involves code execution via the uiconf_id parameter. This parameter can be exploited to write executable PHP code to a web-accessible directory, leading to unauthorized code execution. This requires the file-based cache backend, which is the default configuration for Kaltura.

Recommended Mitigation Strategies

In the absence of a patch, CERT/CC advises administrators to take several precautionary steps. These include blocking or removing the vulnerable endpoint, strictly allowing only legitimate API hosts, rejecting unsafe uiconf_id values, and denying PHP execution in cache directories. Additionally, rotating credentials exposed in local.ini and restricting outbound network access from the server are crucial measures to mitigate risks.

The affected versions include html5lib v2.45, v2.103, and earlier releases that expose the vulnerable endpoint. Wemekamp rated the code execution flaw with a severity score of 10.0 and the file access issue at 9.1. However, CERT/CC has not published official severity scores.

Response and Historical Context

Despite ongoing efforts to report these vulnerabilities to Kaltura since March 2026, the company has not responded or issued a fix. The research highlights a recurring issue with unsafe deserialization, similar to problems faced by other platforms such as Fastjson. Kaltura’s security.txt file indicates a bug bounty program on HackerOne for reporting vulnerabilities, but communication channels have so far yielded no resolution.

As the situation develops, administrators and users of Kaltura’s video platform must remain vigilant and implement the recommended security measures to protect their systems from potential exploitation.

The Hacker News Tags:CERT/CC, code execution, CVE, HTML5 video player, Kaltura, remote access, security flaws, Vulnerabilities

Post navigation

Previous Post: Fake Claude App Exploits Windows, Installs Malware
Next Post: Rethinking MFA: Beyond Authentication to True Identity Security

Related Posts

Critical NVIDIA Container Toolkit Flaw Allows Privilege Escalation on AI Cloud Services Critical NVIDIA Container Toolkit Flaw Allows Privilege Escalation on AI Cloud Services The Hacker News
New RowHammer Attack Variant Degrades AI Models on NVIDIA GPUs New RowHammer Attack Variant Degrades AI Models on NVIDIA GPUs The Hacker News
Gitea Patches Critical RCE Vulnerability in Git Hooks Gitea Patches Critical RCE Vulnerability in Git Hooks The Hacker News
CTM360 Exposes Over 3,000 Phishing URLs in Job Scams CTM360 Exposes Over 3,000 Phishing URLs in Job Scams The Hacker News
Weekly Cybersecurity Recap: ShareFile Threat and More Weekly Cybersecurity Recap: ShareFile Threat and More The Hacker News
How Smart MSSPs Using AI to Boost Margins with Half the Staff How Smart MSSPs Using AI to Boost Margins with Half the Staff The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • OpenAI Blocks Russia-Linked ChatGPT Accounts Over Influence Campaign
  • NovaCookies Exploits Docusign to Hijack Microsoft 365 Sessions
  • 24 Malicious npm Packages Exploit Mirrors for Phishing
  • Rethinking MFA: Beyond Authentication to True Identity Security
  • Kaltura Vulnerabilities Permit Remote File Access and Code Execution

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • OpenAI Blocks Russia-Linked ChatGPT Accounts Over Influence Campaign
  • NovaCookies Exploits Docusign to Hijack Microsoft 365 Sessions
  • 24 Malicious npm Packages Exploit Mirrors for Phishing
  • Rethinking MFA: Beyond Authentication to True Identity Security
  • Kaltura Vulnerabilities Permit Remote File Access and Code Execution

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark