Unpatched Kaltura Server Flaws Enable Code Execution
ID: 6f48694b-73a5-5f73-96fb-9acd55b185d9
STIX ID: report--6f48694b-73a5-5f73-96fb-9acd55b185d9
Feed Name: securityonline.info
Kaltura's HTML5 Player library contains two critical unpatched vulnerabilities: one permits reading local files (CVE-2026-19913) and the other enables remote code execution (CVE-2026-19912) through insecure deserialization of a user-controlled ServiceUrl. Affected v2.x releases (including 2.45 and 2.103) may allow attackers to steal credentials, alter data, or gain full server control and pose additional risk to tenants on shared CDN infrastructure; no vendor patch or public exploit has been confirmed, so administrators are advised to restrict or disable the vulnerable endpoint immediately.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
