
🚨 CRITICAL REDCAP RCE DISCLOSED — PUBLIC SURVEY CONTEXT CAN LEAD TO SERVER CODE EXECUTION A newly published vulnerability in Vanderbilt University's REDCap research-data platform allows remote code execution without authentication. • CVE-2026-90817 — CVSS 9.8 Critical • Published September 20, 2026 • The flaw affects REDCap's survey passthrough routing and Data Import processing logic • An attacker can manipulate HTTP requests to reach an unintended controller route and supply a crafted file-path/stream parameter • Successful exploitation can execute arbitrary code on the REDCap server • Authentication is NOT required • Exploitation does require knowledge of a valid public survey hash — notable because public survey links are designed to be distributed externally • The CVE record describes REDCap 13.3.0 and higher as affected; structured version data lists 16.0.49, 17.3.10 and 17.4.4 as unaffected releases • No public PoC or confirmed in-the-wild exploitation has been identified at this time ⚠️ Analyst Note: REDCap is used for research and clinical data collection, making server-side compromise potentially significant where deployments contain sensitive study or participant information. The attack prerequisite is also unusual: rather than requiring an account, the attacker needs a valid public survey hash. Organizations operating internet-facing REDCap deployments should verify their exact version and remediation status immediately. Original CVE record: https://www.cve.org/CVERecord?id=CVE-2026-90817 #REDCap #CVE202690817 #RCE #Vulnerability #HealthcareSecurity #CyberSecurity #ThreatIntel #DDW #DarkWeb



