External risk intelligence

Kaltura HTML5 Player Unsafe Deserialization RCE Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2026-19912

The vulnerability resides in a video player's loader script, which is typically deployed as a web-accessible component within public-facing websites to handle media delivery. As it processes user-controlled input directly from the web request to manage configuration and caching, it constitutes a web application endpoint commonly reachable from the internet.

Path Traversal

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical vulnerability in a widely used video player could allow attackers to execute malicious code on web servers. This issue stems from how the player processes and stores data, potentially enabling unauthorized file writes to web-accessible locations.

  • Unsafe player code lets attackers run commands.
  • Critical player flaw, widely deployed on websites.
  • Confirm if our video player technology is affected.

Attack Path

How an attacker could exploit the issue

An attacker can exploit this vulnerability by sending specially crafted requests to the Kaltura HTML5 player's loader script. This script processes a user-controlled URL and uses parts of the response, along with a user-supplied ID, to construct a file path for caching. Because the path construction is not properly validated, an attacker can trick the system into writing arbitrary files to a web-accessible location, ultimately leading to code execution with the privileges of the web server.

  • Entry Condition: Publicly accessible web endpoint.
  • Trigger Point: User-controlled URL and ID.
  • Resulting Risk: Arbitrary file write and code execution.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow an unauthenticated attacker to execute arbitrary code on the webserver by writing malicious files to web-accessible locations. This occurs when the Kaltura HTML5 player processes user-supplied data without adequate validation, leading to unsafe deserialization and unsanitized file path construction. The attacker could leverage this to compromise the webserver environment.

  • Webserver files and code execution.
  • Unsanitized input allows arbitrary file writes.
  • Compromise of the webserver environment.

Operational Fix

Recommended remediation, mitigation, and detection steps

The Kaltura HTML5 player's unauthenticated remote code execution vulnerability requires immediate attention from teams managing web applications and content delivery. The first practical step is to identify all instances of the affected player, determine their exposure and criticality, and then assign ownership for remediation planning. This includes coordinating with any vendor-management teams if the player is part of a third-party solution.

  • Application owners should confirm asset inventory.
  • Verify exposure and business criticality of instances.
  • Plan remediation with vendor or internal teams.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the Kaltura HTML5 player?

The Kaltura HTML5 player, specifically the mwEmbed or html5lib component, is a media delivery tool integrated into websites to handle video playback. It functions as a client-side and server-side framework that enables browsers to display video content while managing configuration settings and caching media data dynamically.

What does unsafe deserialization mean for CVE-2026-19912?

This vulnerability involves the weakness classes CWE-20 (Improper Input Validation) and CWE-22 (Improper Limitation of a Pathname). It occurs when the player blindly trusts data received from an external URL. By processing this untrusted input through a deserialization function, the system can be manipulated into executing unintended code or writing malicious files to the server’s filesystem.

How can an attacker trigger this vulnerability?

An attacker triggers this by sending a crafted network request to the player's loader script, providing a malicious URL and a specific ID. Simply accessing the player for normal video viewing does not trigger the bug; the attacker must intentionally supply specially formatted inputs that manipulate the server's file path construction and data processing logic.

Is my server at risk from this Kaltura player issue?

If you host instances of the Kaltura HTML5 player that are reachable from the internet, your server is at risk. Halo Surface Signal notes that because the affected loader script is a web-accessible component used for media delivery, it often creates an endpoint that is directly exposed to public traffic, making it a primary target for remote attacks.

How do I start protecting my systems against this?

Begin by auditing your digital infrastructure to locate every instance of the Kaltura HTML5 player currently in use. Once identified, categorize these assets based on their criticality and network exposure. If you use the player through a third-party service, reach out to your vendor immediately to confirm if they have deployed necessary updates to mitigate this risk.

References