CVE-2026-19913 is an unpatched vulnerability in Kaltura's mwEmbedLoader.php that allows remote, unauthenticated attackers to read arbitrary files from the server. The flaw is due to unsafe deserialization of data fetched via the ServiceUrl parameter, which can be set to a file:// path. The server reflects the raw bytes of the file in an error message, enabling disclosure of sensitive data such as database credentials. The researcher assigned a CVSS score of 9.1.