CVE-2026-77615: Opencast
High severity, CVSS 8.7. EPSS: 0.6% chance of exploitation in the next 30 days.
Paella Player is a set of libraries to create a multi stream video player. Prior to Paella Player 2.12.11 (as used in Opencast prior to 19.7 and 20.2), there is a potential XSS attack though closed captions cue text. This vulnerability is fixed in 2.12.11.
Affected products
- Opencast Opencast: before 19.7 (fixed in 19.7); from 20.0, before 20.2 (fixed in 20.2)
- Polimediaupv Paella-Player: before 2.12.11 (fixed in 2.12.11)
Published 2026-09-17. Last modified 2026-09-24.