Junglewise Threat Intelligence

CVE-2026-73090: PeerTube authorization bypass in ActivityPub video updates

CVE-2026-73090 · Severity: critical · CVSS 9.3 · Published 2026-08-11

Executive brief

PeerTube is a federated video streaming platform that allows independent servers to share content with each other. A malicious federated server can exploit this vulnerability to modify another server's videos—including changing visibility, replacing media files, and rewriting streaming URLs—without proper permission checks. This allows attackers to corrupt or hijack video content across federated instances.

Technical details

The vulnerability exists in the processUpdateActivity and processUpdateVideo functions, which fail to verify that the actor sending an ActivityPub Update activity is authorized to modify the video being updated. Specifically, the code does not check that byActor.url matches the host of videoObject.id before accepting metadata, visibility, media file, and HLS URL changes. An attacker controlling a federated server can send a crafted Update activity to modify videos hosted on other instances. The fix (released in version 8.2.2) adds host-matching validation to ensure actors and videos belong to the same host before processing updates.

Affected products

  • PeerTube PeerTube prior to 8.2.2

Timeline

  • 2026-08-11: disclosed
  • 2026-07-02: patched: Fix released in version 8.2.2

References