CyberSecurityBoardThreat Intel · CVEs · Products
Cyber Products

mwEmbed: Kaltura’s HTML5 Video Player Library with Critical Flaws

August 26, 2026

mwEmbed is Kaltura's HTML5 video player library, also distributed as html5lib. It contains two unpatched vulnerabilities (CVE-2026-19912 and CVE-2026-19913) in the mwEmbedLoader.php endpoint, allowing remote code execution and arbitrary file read. The library is exposed on customer installations and Kaltura's shared multi-tenant CDN infrastructure, affecting all tenants.