Until a patch is released, organizations using Kaltura's mwEmbed library should monitor for updates from Kaltura, restrict network access to the mwEmbedLoader.php endpoint where possible, and implement input validation and monitoring for deserialization-related anomalies.
Quick answers
What is CVE-2026-19913?
Until a patch is released, organizations using Kaltura's mwEmbed library should monitor for updates from Kaltura, restrict network access to the mwEmbedLoader.php endpoint where possible, and implement input validation and monitoring for deserialization-related anomalies.
How severe is CVE-2026-19913?
high
Is CVE-2026-19913 known to be exploited?
It is not marked known-exploited in this record.
How should CVE-2026-19913 be mitigated?
Until a patch is released, organizations using Kaltura's mwEmbed library should monitor for updates from Kaltura, restrict network access to the mwEmbedLoader.php endpoint where possible, and implement input validation and monitoring for deserialization-related anomalies.
CVSS
—
Vendor
Kaltura
Published
Sep 30, 2026 · 08:05
Patch
Unknown / not confirmed
Affected products
HTML5 video player library
Mitigation
Until a patch is released, organizations using Kaltura's mwEmbed library should monitor for updates from Kaltura, restrict network access to the mwEmbedLoader.php endpoint where possible, and implement input validation and monitoring for deserialization-related anomalies.
The CERT Coordination Center (CERT/CC) has disclosed two unpatched vulnerabilities in Kaltura's HTML5 video player library. Tracked as CVE-2026-19913 and CVE-2026-19912, the flaws stem from unsafe deserialization in the mwEmbedLoader.php endpoint. A remote, unauthenticated attacker can exploit these weaknesses to read arbitrary files from the server and execute arbitrary code. No patch is currently available, and exploitation in the wild has not been confirmed at the time of disclosure.