Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.8
CVE-2026-73211: PeerTube: Unauthenticated SQL injection allows database takeover
CVE-2026-73211
CVE-2026-73211
Summary
PeerTube's database security was compromised, allowing unauthorized access to sensitive data and administrative accounts. This issue has been fixed in version 8.1.6, so update your PeerTube installation to this version to protect your system. Regularly updating PeerTube is essential to ensure the security of your video streaming platform.
What to do
No fix is available yet. Check with your software vendor for updates.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| chocobozzz | peertube | < 8.1.6 |
Original title
PeerTube is an ActivityPub-federated video streaming platform. Prior to 8.1.6, ActorFollowModel.updateScore() interpolates the attacker-controlled ActivityPub actor inboxUrl into an SQL query, allo...
Original description
PeerTube is an ActivityPub-federated video streaming platform. Prior to 8.1.6, ActorFollowModel.updateScore() interpolates the attacker-controlled ActivityPub actor inboxUrl into an SQL query, allowing an unauthenticated remote server to read and write PeerTube database tables, including oAuthToken.accessToken, and take over administrator accounts. This issue is fixed in version 8.1.6.
nvd CVSS3.1
9.8
Vulnerability type
CWE-89
SQL Injection
Published: 11 Aug 2026 · Updated: 11 Aug 2026 · First seen: 11 Aug 2026