A newly discovered vulnerability in Kaltura’s mwEmbed plugin has left hundreds of thousands of websites vulnerable to remote attacks, allowing attackers to read sensitive files and execute arbitrary code. The unpatched flaw, disclosed on Wednesday, affects all versions of the plugin, making it a pressing concern for organizations that rely on the popular video management system.
Kaltura’s mwEmbed is widely used by content providers, educational institutions, and media companies to embed videos on their websites. However, researchers have found that a bug in the plugin’s handling of cross-domain requests enables an attacker to escalate privileges and gain unauthorized access to sensitive areas of the affected website. This vulnerability can be exploited remotely, making it a prime target for hackers.
The attack path is relatively straightforward: an attacker crafts a malicious request that tricks the mwEmbed plugin into granting excessive permissions. Once inside, the attacker can read sensitive files, inject malware, or even take control of the entire system. The severity of this flaw is further compounded by the fact that Kaltura has yet to issue a patch, leaving many websites exposed.
Organizations that use Kaltura’s mwEmbed plugin should be on high alert, as the vulnerability affects all versions of the software. While Kaltura has acknowledged the issue and promised a fix soon, website administrators are left with limited options until a patch is released. In the meantime, organizations may want to consider implementing temporary mitigations, such as restricting cross-domain requests or configuring their web application firewall to block malicious traffic.
The impact of this vulnerability extends beyond just websites that use Kaltura’s mwEmbed plugin. As more and more organizations rely on video management systems like Kaltura, the risk of supply chain attacks increases. Attackers can exploit vulnerabilities in third-party plugins to gain access to sensitive areas of a website, making it essential for organizations to prioritize patching and stay up-to-date with security advisories.
To minimize their exposure, we recommend that websites using Kaltura’s mwEmbed plugin take immediate action: review their configuration settings, restrict cross-domain requests, and ensure their web application firewall is configured to block malicious traffic. While a patch is being developed, these temporary measures can help prevent attackers from exploiting the vulnerability.
Source: The Hacker News — 2026-08-26