Executive brief
Kaltura's HTML5 Player (an open-source video playback library used in many web applications) contains a flaw that allows unauthenticated attackers to read sensitive files from the server. By manipulating the ServiceUrl parameter, an attacker can trick the player into fetching internal files (like database credentials or API keys) and returning their contents in error messages, potentially compromising the entire Kaltura deployment or multi-tenant hosting infrastructure.
Technical details
CVE-2026-19913 is a local file disclosure vulnerability in the Kaltura HTML5 Player (mwEmbed / html5lib) stemming from improper validation of the ServiceUrl parameter in mwEmbedLoader.php. The vulnerable code accepts non-HTTP schemes (such as file://) without validation, passes them to the KalturaClientBase PHP client, and automatically deserializes responses using PHP's unserialize() function. When deserialization fails on a local file's raw bytes, the error handler reflects the file contents back to the client. An unauthenticated, network-accessible attacker can exploit this to read arbitrary files accessible to the web-server user by crafting malicious requests with file:// URLs. Affected versions include html5lib v2.45, v2.103, and other v2.x releases of the legacy Player V2; the currently supported Player V7 is not affected. Patches are available; until applied, access to mwEmbedLoader.php should be restricted.
Affected products
- Kaltura HTML5 Player v2.45, v2.103, and other v2.x releases
Timeline
- 2026-08-25: disclosed
- 2026-08-25: patched: Patches released for all affected legacy Player V2 versions