Remote Code Execution Vulnerability in Kaltura HTML5 Player
CVE-2026-19912
Currently unrated
What is CVE-2026-19912?
The Kaltura HTML5 player is susceptible to a remote code execution vulnerability due to the unsafe handling of user-supplied data. Specifically, when the mwEmbedLoader.php script processes the ServiceUrl provided by an attacker, it performs deserialization without adequate validation. This exploitation can allow an attacker to manipulate the uiconf_id and write malicious files to locations accessible by the web server. This vulnerability affects multiple versions of html5lib, making it crucial for users to review their deployments and apply necessary security measures to prevent unauthorized code execution.
Affected Version(s)
Kaltura HTML5 Video Player, html5 library 0
Kaltura HTML5 Video Player, html5 library 2.45
