CVE-2026-73211: PeerTube: Unauthenticated remote SQL injection in ActorFollowModel.updateScore()
PeerTube is an ActivityPub-federated video streaming platform. Prior to 8.1.6, ActorFollowModel.updateScore() interpolates the attacker-controlled ActivityPub actor inboxUrl into an SQL query, allowing an unauthenticated remote server to read and write PeerTube database tables, including oAuthToken.accessToken, and take over administrator accounts. This issue is fixed in version 8.1.6.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
PeerTubeto a version that resolves this vulnerability.Fixed in 8.1.6
Event History
Frequently Asked Questions
What is the severity of CVE-2026-73211?
The severity of CVE-2026-73211 is classified as critical with a score of 9.8.
How do I fix CVE-2026-73211?
To fix CVE-2026-73211, you should upgrade to PeerTube version 8.1.6 or later.
What types of systems are affected by CVE-2026-73211?
CVE-2026-73211 affects PeerTube installations prior to version 8.1.6.
What kind of vulnerability is CVE-2026-73211?
CVE-2026-73211 is an unauthenticated remote SQL injection vulnerability.
What data could be compromised due to CVE-2026-73211?
Due to CVE-2026-73211, an attacker could potentially read and write PeerTube database tables, including sensitive information like oAuthToken.