logo

Unpatched Kaltura Server Flaws Enable Code Execution

ID: 6f48694b-73a5-5f73-96fb-9acd55b185d9

STIX ID: report--6f48694b-73a5-5f73-96fb-9acd55b185d9

Feed Name: securityonline.info

Threat Score
72/100

Date Published: 2026-08-25

Date Updated: 2026-08-26

Author: Do Son

...
...

Kaltura's HTML5 Player library contains two critical unpatched vulnerabilities: one permits reading local files (CVE-2026-19913) and the other enables remote code execution (CVE-2026-19912) through insecure deserialization of a user-controlled ServiceUrl. Affected v2.x releases (including 2.45 and 2.103) may allow attackers to steal credentials, alter data, or gain full server control and pose additional risk to tenants on shared CDN infrastructure; no vendor patch or public exploit has been confirmed, so administrators are advised to restrict or disable the vulnerable endpoint immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.