← All CVEs NewScan detects
critical

CVE-2026-73090

PeerTube cross-origin video takeover via a federated Update activity

Severity
critical
Affected product
PeerTube
Affected versions
PeerTube ≥ 8.1.6, < 8.2.2
Fixed in
PeerTube 8.2.2
Added to NewScan
2026-08-12
Detected by
NewScan — free, self-hosted

How NewScan reports it

COMPONENT VERSION RANGE

NewScan fingerprints PeerTube from its response and reports this CVE when the detected version falls inside the affected range below.

The window where the SQL injection above is already fixed and the takeover is not: 8.1.6 through 8.2.1. Split from the row above rather than overlapping it so one install yields ONE finding naming exactly the ids that still apply - an overlap would report the patched SQLi again on every 8.2.x. See the lt-8.1.6 row for both advisories.

References

Scan for this yourself — local, in-band scanning is free.

Get NewScan (FREE) →