All incidents

Unpatched Kaltura HTML5 player flaws allow file read and code execution

vulnerabilityopenAug 25, 2026 — Aug 26, 2026
Kaltura mwEmbed unpatched flaws allow file read, code execution

A pair of unpatched vulnerabilities in the Kaltura mwEmbed library have been disclosed, allowing unauthenticated attackers to read local files and execute arbitrary code on vulnerable web servers, according to a CERT advisory published today.

The flaws reside in the mwEmbedLoader.php endpoint and affect html5lib version 2.45 and earlier releases of the Kaltura HTML5 Player Library.

The issues arise from an insecure deserialization process in the KalturaClient component, where malicious serialized data sent to mwEmbedLoader.php can be abused to read files and run code.

Details of the vulnerability were highlighted by SecurityOnline, which noted that no authentication is required and that successful exploitation could expose database credentials and API keys here.

Any web server running the affected html5lib versions is potentially at risk, as the vulnerable endpoint is accessible without any form of authentication.

Because the flaw does not rely on user interaction, attackers can send crafted requests remotely to achieve full control of the underlying system.

At the time of writing there have been no public reports of active exploitation, but the CERT warning stresses that the simplicity of the attack vector makes it likely to be targeted by opportunistic actors.

No specific threat groups have been linked to the issue, yet the widespread use of Kaltura in video‑sharing platforms and educational services increases the potential impact should the flaw be weaponised.

Administrators should restrict access to mwEmbedLoader.php to trusted IP addresses only, enforce an allow‑list of permitted URLs for the endpoint, and monitor web server logs for unexpected or malformed requests.

If the library is not required for operations, consider disabling it until an official patch is released, and deploy a web application firewall rule that blocks known deserialization payloads to mitigate the threat in the interim.

In the longer term, track Kaltura’s security advisories for a fixed version, upgrade the html5lib component as soon as a patched release is made available, and review inventories of third‑party JavaScript libraries for similar deserialization risks.

Finally, ensure that the web server process runs with the least privileges necessary to limit the consequences of any future file‑read or code‑execution attempt.

Intelligence briefing updated Aug 26, 2026

Root sourcekb.cert.org
Timeline Coverage

Swipe to explore timeline