CyberSecurityBoardThreat Intel · CVEs · Products
Critical CVEs

CVE-2026-19912: Kaltura mwEmbed Remote Code Execution via Unsafe Deserialization

August 26, 2026

CVE-2026-19912 is an unpatched vulnerability in Kaltura's mwEmbedLoader.php that allows remote, unauthenticated code execution. The flaw stems from unsafe deserialization of data fetched via the ServiceUrl parameter, combined with a path traversal in the uiconf_id parameter that enables writing a malicious PHP payload to a web-accessible directory. The researcher assigned a CVSS score of 10.0, though CERT/CC has not published an official score.