CVE-2026-73090

PeerTube: Cross-origin remote video takeover via Update activity

PeerTube is an ActivityPub-federated video streaming platform. Prior to 8.2.2, processUpdateActivity and processUpdateVideo accept an ActivityPub Update containing a Video object without verifying that byActor.url is authorized for the host in videoObject.id, allowing a malicious federated server to rewrite another server's video metadata, visibility, media file, and HLS URLs. This issue is fixed in version 8.2.2.


We have discovered 367 live websites that are affected by CVE-2026-73090.

Run a Free Instant Scan




Affected Software

Product  PeerTube
Category Message Boards
Vulnerable Domains367 live websites (76% of PeerTube install base)
Vulnerable Versions
  • from 0 through 8.2.2
Vulnerable Versions Count37 versions ( 95% of all versions)


Common Weakness Enumeration

CWE-863 Incorrect Authorization



Details

  • Published - Aug 11, 2026
  • Updated - Aug 13, 2026

Website Distribution by Country

Number of websites using CVE-2026-73090
United States44 websites



France121 websites
Germany91 websites
Russia38 websites
Spain9 websites
Czech Republic7 websites
GB5 websites
Canada5 websites
Belgium4 websites
Singapore4 websites

Website Distribution by TLD

Number of websites using CVE-2026-73090
.com54 websites
.fr44 websites
.org36 websites
.net31 websites
.de29 websites
.ru28 websites
.eu10 websites
.es7 websites
.pl4 websites
.cz4 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-73090

Top websites that are affected by CVE-2026-73090. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*****.zone United States***,***
****.tube France***,***
*****.*****.fr France***,***
********.br Brazil***,***
****.******.de Germany*,***,***
*****.tube France*,***,***
****.*********.global Germany*,***,***
********.**********.tv Germany*,***,***
********.*************.fr France*,***,***
*****.*****.it Italy*,***,***
See full domain list

FAQ

CVE-2026-73090 is Incorrect Authorization in PeerTube
A total of 367 websites have been identified as vulnerable to CVE-2026-73090, based on global website indexing conducted by WebTechSurvey.
The PeerTube is affected by the CVE-2026-73090 vulnerability.
PeerTube versions up to 8.2.2 are vulnerable to CVE-2026-73090.
CVE-2026-73090 is resolved in version 8.2.2 of PeerTube.