PoC public mwEmbed rce html5lib Kaltura info-disclosure
Unpatched Kaltura mwEmbed Flaws Could Let Remote Attackers Read Files and Run Code
CVE Tools coverage
CERT/CC has disclosed two critical, unpatched vulnerabilities in the Kaltura mwEmbed player library, specifically affecting html5lib versions v2.45 and v2.103 and earlier. The flaws, identified as CVE-2026-19913 and CVE-2026-19912, originate from unsafe deserialization in the mwEmbedLoader.php endpoint, allowing unauthenticated remote attackers to read arbitrary files and execute code without requiring a valid session token. Although no official patch is currently available because the vendor could not be reached, administrators are advised to immediately restrict external access to the endpoint and enforce strict allow-lists for the ServiceUrl parameter to mitigate these risks.