PatchSiren cyber security CVE debrief
CVE-2026-73090 Chocobozzz CVE debrief
A critical vulnerability was found in PeerTube, a video streaming platform, which allows a malicious federated server to rewrite video metadata, visibility, media files, and HLS URLs of another server. This issue, fixed in version 8.2.2, has a CVSS score of 9.3 and is considered critical. The vulnerability exists due to the lack of verification of the byActor.url in processUpdateActivity and processUpdateVideo, allowing potential metadata tampering and unauthorized access to video content. Defenders responsible for PeerTube instances, video streaming platforms, and federated servers should assess exposure and prioritize updates to prevent potential security risks.
- Vendor
- Chocobozzz
- Product
- PeerTube
- CVSS
- CRITICAL 9.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-11
- Original CVE updated
- 2026-09-09
- Advisory published
- 2026-08-11
- Advisory updated
- 2026-09-09
Who should care
Defenders responsible for PeerTube instances, video streaming platforms, and federated servers should assess exposure and prioritize updates to prevent potential metadata tampering and unauthorized access.
Why it matters
A critical vulnerability in PeerTube allows a malicious federated server to rewrite video metadata, visibility, media files, and HLS URLs of another server, requiring immediate attention from defenders.
- Potential metadata tampering and unauthorized access to video content
- Possible disruption of video streaming services
- Need for verification of video metadata and content
- Priority for updating PeerTube to version 8.2.2 or later
Technical summary
PeerTube, a video streaming platform, is vulnerable to a critical issue (CVE-2026-73090) that allows a malicious federated server to rewrite video metadata, visibility, media files, and HLS URLs of another server. This is due to the lack of verification of the byActor.url in processUpdateActivity and processUpdateVideo. The issue has a CVSS score of 9.3 and is fixed in version 8.2.2. The vulnerability allows potential metadata tampering and unauthorized access to video content, requiring immediate attention from defenders. Affected product deployments should be reviewed, and updates should be prioritized to prevent security risks.
Defensive priority
Defenders should prioritize updating PeerTube to version 8.2.2 or later to prevent potential metadata tampering and unauthorized access to video content.
Recommended defensive actions
- Update PeerTube to version 8.2.2 or later
- Review and verify video metadata and content for potential tampering
- Monitor for suspicious activity on federated servers
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
Evidence notes
The CVE record and NVD entry provide details on the vulnerability, its impact, and the fixed version. However, the scope of affected versions and potential exploitation remains limited to the information provided by the CVE Program and NVD.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-73090 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-73090
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-73090 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-73090
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/Chocobozzz/PeerTube/commit/63d487d2a4a2a0e36af8c0ccb888cd23725bf7f2
-
Source reference
Unverified legacy reference
URL: https://github.com/Chocobozzz/PeerTube/releases/tag/v8.2.2
-
Source reference
Unverified legacy reference
URL: https://github.com/Chocobozzz/PeerTube/security/advisories/GHSA-g9p4-f7h8-hc86
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.