CVE-2026-73211Active Exploitation

LOWCVSS 9.8 · CRITICAL

Exploitation ongoing with high activity in latest observed window (2 mentions)

Immediate actions

  • Prioritize remediation for affected systems immediately
  • Assume compromise if assets are exposed
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

PeerTube is an ActivityPub-federated video streaming platform. Prior to 8.1.6, ActorFollowModel.updateScore() interpolates the attacker-controlled ActivityPub actor inboxUrl into an SQL query, allowing an unauthenticated remote server to read and write PeerTube database tables, including oAuthToken.accessToken, and take over administrator accounts. This issue is fixed in version 8.1.6.

3.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-89

Priority

LOW

Exploitation

ACTIVE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • Active exploitation appears in 1 classified signals
  • 2 mentions across 1 observed day

What's happening

  • Active exploitation reported across 1 signal
  • Technical details provided in 1 signal
  • General: 1 classified signal
  • 2 total mentions across 1 day

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-08-12: 2Active Exploitation · 2026-08-12: 1Technical Details · 2026-08-12: 108-12
Signal classification2 categories
Active Exploitation
150.0%
General
150.0%
Referenced assets2 URLs
Full discourse2 posts
  • Veriti Spottr@veritispottr
    General

    LOW Alert (CVE-2026-73211): PeerTube vulnerability Read more: https://threat.veritispottr.com #CyberSecurity #ThreatIntel #InfoSec

    Post summary

    A low‑severity alert for CVE‑2026‑73211, a PeerTube vulnerability, is posted with a link to additional information, but it contains no PoC, exploit, active exploitation, patch, or technical details.

    0001044
    223 followersView on X
  • NewNormal Security@NewScanTeam
    Active Exploitation

    NewNormal Security turns the last 24 hours of CVEs into new detections, every day. 𝗗𝗮𝗶𝗹𝘆 𝗖𝗩𝗘 𝗥𝗲𝗽𝗼𝗿𝘁 — 12 Aug 2026 𝗔𝗱𝗱𝗲𝗱 to NewScan 𝘁𝗼𝗱𝗮𝘆: 💉 Unauthenticated SQL injection from a federated peer — another server injects SQL with no account on yours, reads the token table and takes over an admin (PeerTube CVE-2026-73211) 🔓 Cross-origin takeover of a published video — a hostile peer rewrites another server's video metadata, visibility and media URLs (PeerTube CVE-2026-73090) 📦 Actively-exploited advisory match on a VPN appliance — one unauthenticated request reloads the firewall and drops remote access for the whole workforce (Cisco CVE-2026-20349) Test your stack with NewScan — free, self-hosted: https://newnormalsecurity.com/newscan?utm_source=x&utm_medium=social&utm_campaign=daily-cve&s=x #infosec #AppSec #SQLi #CSO #REDTEAM

    Post summary

    The report lists daily CVEs with technical details, noting one as actively exploited, but it does not provide PoC or exploit code.

    0000062
    5 followersView on X

Explore more