Two unpatched Kaltura mwEmbed flaws allow unauthenticated file read and could enable RCE through unsafe deserialization.