CyberSecurityBoardThreat Intel · CVEs · Products
Critical CVEs

CVE-2026-19913: Kaltura mwEmbed Arbitrary File Read via Unsafe Deserialization

August 26, 2026

CVE-2026-19913 is an unpatched vulnerability in Kaltura's mwEmbedLoader.php that allows remote, unauthenticated attackers to read arbitrary files from the server. The flaw is due to unsafe deserialization of data fetched via the ServiceUrl parameter, which can be set to a file:// path. The server reflects the raw bytes of the file in an error message, enabling disclosure of sensitive data such as database credentials. The researcher assigned a CVSS score of 9.1.