CVE-2026-73211

PeerTube: Unauthenticated remote SQL injection in ActorFollowModel.updateScore()

PeerTube is an ActivityPub-federated video streaming platform. Prior to 8.1.6, ActorFollowModel.updateScore() interpolates the attacker-controlled ActivityPub actor inboxUrl into an SQL query, allowing an unauthenticated remote server to read and write PeerTube database tables, including oAuthToken.accessToken, and take over administrator accounts. This issue is fixed in version 8.1.6.


We have discovered 228 live websites that are affected by CVE-2026-73211.

Run a Free Instant Scan




Affected Software

Product  PeerTube
Category Message Boards
Vulnerable Domains228 live websites (47% of PeerTube install base)
Vulnerable Versions
  • from 0 through 8.1.6
Vulnerable Versions Count34 versions ( 87% of all versions)


Common Weakness Enumeration

CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')



Details

  • Published - Aug 11, 2026
  • Updated - Aug 11, 2026

Website Distribution by Country

Number of websites using CVE-2026-73211
United States28 websites



France71 websites
Germany64 websites
Russia14 websites
Czech Republic6 websites
Spain5 websites
GB5 websites
Belgium4 websites
Switzerland3 websites

Website Distribution by TLD

Number of websites using CVE-2026-73211
.com37 websites
.org25 websites
.de23 websites
.fr22 websites
.net21 websites
.es6 websites
.eu6 websites
.ru5 websites
.co.uk3 websites
.cz3 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-73211

Top websites that are affected by CVE-2026-73211. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*****.zone United States***,***
****.tube France***,***
*****.*****.fr France***,***
********.br Brazil***,***
****.******.de Germany*,***,***
*****.tube France*,***,***
****.*********.global Germany*,***,***
********.**********.tv Germany*,***,***
*****.*****.it Italy*,***,***
******.*********.xyz United States*,***,***
See full domain list

FAQ

CVE-2026-73211 is Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in PeerTube
A total of 228 websites have been identified as vulnerable to CVE-2026-73211, based on global website indexing conducted by WebTechSurvey.
The PeerTube is affected by the CVE-2026-73211 vulnerability.
PeerTube versions up to 8.1.6 are vulnerable to CVE-2026-73211.
CVE-2026-73211 is resolved in version 8.1.6 of PeerTube.