PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-73090 Chocobozzz CVE debrief

A critical vulnerability was found in PeerTube, a video streaming platform, which allows a malicious federated server to rewrite video metadata, visibility, media files, and HLS URLs of another server. This issue, fixed in version 8.2.2, has a CVSS score of 9.3 and is considered critical. The vulnerability exists due to the lack of verification of the byActor.url in processUpdateActivity and processUpdateVideo, allowing potential metadata tampering and unauthorized access to video content. Defenders responsible for PeerTube instances, video streaming platforms, and federated servers should assess exposure and prioritize updates to prevent potential security risks.

Vendor
Chocobozzz
Product
PeerTube
CVSS
CRITICAL 9.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-11
Original CVE updated
2026-09-09
Advisory published
2026-08-11
Advisory updated
2026-09-09

Who should care

Defenders responsible for PeerTube instances, video streaming platforms, and federated servers should assess exposure and prioritize updates to prevent potential metadata tampering and unauthorized access.

Why it matters

A critical vulnerability in PeerTube allows a malicious federated server to rewrite video metadata, visibility, media files, and HLS URLs of another server, requiring immediate attention from defenders.

  • Potential metadata tampering and unauthorized access to video content
  • Possible disruption of video streaming services
  • Need for verification of video metadata and content
  • Priority for updating PeerTube to version 8.2.2 or later

Technical summary

PeerTube, a video streaming platform, is vulnerable to a critical issue (CVE-2026-73090) that allows a malicious federated server to rewrite video metadata, visibility, media files, and HLS URLs of another server. This is due to the lack of verification of the byActor.url in processUpdateActivity and processUpdateVideo. The issue has a CVSS score of 9.3 and is fixed in version 8.2.2. The vulnerability allows potential metadata tampering and unauthorized access to video content, requiring immediate attention from defenders. Affected product deployments should be reviewed, and updates should be prioritized to prevent security risks.

Defensive priority

Defenders should prioritize updating PeerTube to version 8.2.2 or later to prevent potential metadata tampering and unauthorized access to video content.

Recommended defensive actions

  • Update PeerTube to version 8.2.2 or later
  • Review and verify video metadata and content for potential tampering
  • Monitor for suspicious activity on federated servers
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review

Evidence notes

The CVE record and NVD entry provide details on the vulnerability, its impact, and the fixed version. However, the scope of affected versions and potential exploitation remains limited to the information provided by the CVE Program and NVD.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-73090 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-73090

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-73090 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-73090

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.