VU#308749: Remote Code Execution and Arbitrary File Read Vulnerabilities in Kaltura Servers

CERT Coordination Center Version 2 imported change current

Imported from official source

Overview The Kaltura HTML5 Player V2 Library (mwEmbed / html5lib) contains two vulnerabilities, both involving the same insecure deserialization flaw, that enable arbitrary file read and remote code execution. Affected versions include html5lib v2.45, v2.103 and earlier, and other v2.x releases that expose the vulnerable mwEmbedLoader.php endpoint. …

This version

Version
2 of 2
Recorded
September 18, 2026 09:42
Change
Imported change
Content hash
553c8fdc57c4186c4466bff6114686af
All versions
Revision history

Officially records where a publication came from, not whether it is true. Imported records are reproduced from an organization's own official source.