CVE-2026-77615: Opencast

High severity, CVSS 8.7. EPSS: 0.6% chance of exploitation in the next 30 days.

Paella Player is a set of libraries to create a multi stream video player. Prior to Paella Player 2.12.11 (as used in Opencast prior to 19.7 and 20.2), there is a potential XSS attack though closed captions cue text. This vulnerability is fixed in 2.12.11.

Affected products

  • Opencast Opencast: before 19.7 (fixed in 19.7); from 20.0, before 20.2 (fixed in 20.2)
  • Polimediaupv Paella-Player: before 2.12.11 (fixed in 2.12.11)

Published 2026-09-17. Last modified 2026-09-24.