critical
CVE-2026-73090
PeerTube cross-origin video takeover via a federated Update activity
- Severity
- critical
- Affected product
- PeerTube
- Affected versions
- PeerTube ≥ 8.1.6, < 8.2.2
- Fixed in
- PeerTube 8.2.2
- Added to NewScan
- 2026-08-12
- Detected by
- NewScan — free, self-hosted
How NewScan reports it
COMPONENT VERSION RANGE
NewScan fingerprints PeerTube from its response and reports this CVE when the detected version falls inside the affected range below.
The window where the SQL injection above is already fixed and the takeover is not: 8.1.6 through 8.2.1. Split from the row above rather than overlapping it so one install yields ONE finding naming exactly the ids that still apply - an overlap would report the patched SQLi again on every 8.2.x. See the lt-8.1.6 row for both advisories.
References
Scan for this yourself — local, in-band scanning is free.
Get NewScan (FREE) →