Remote Code Execution Vulnerability in Kaltura HTML5 Player
CVE-2026-19912

Currently unrated

Key Information:

Vendor

Kaltura

Vendor
CVE Published:
25 August 2026

What is CVE-2026-19912?

The Kaltura HTML5 player is susceptible to a remote code execution vulnerability due to the unsafe handling of user-supplied data. Specifically, when the mwEmbedLoader.php script processes the ServiceUrl provided by an attacker, it performs deserialization without adequate validation. This exploitation can allow an attacker to manipulate the uiconf_id and write malicious files to locations accessible by the web server. This vulnerability affects multiple versions of html5lib, making it crucial for users to review their deployments and apply necessary security measures to prevent unauthorized code execution.

Affected Version(s)

Kaltura HTML5 Video Player, html5 library 0

Kaltura HTML5 Video Player, html5 library 2.45

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.