CVE-2026-90817

LOWCVSS 9.8 · CRITICAL

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

An unauthenticated Remote Code Execution vulnerability was found in the survey passthrough routing and Data Import processing logic, in which a malicious user could potentially exploit it by manipulating HTTP requests to access an unintended controller route from a public survey context and by supplying a crafted file-path/stream parameter during import handling. If successfully exploited, this could allow the attacker to remotely execute arbitrary code on the REDCap server. The attacker does not have to be authenticated in order to exploit this, but exploitation requires knowledge of a valid public survey hash. This vulnerability exists in REDCap 13.3.0 and higher.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-73CWE-94

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Peaked at 3 mentions on most recent observed day (2026-09-21)
  • 4 total mentions across 2 days

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-09-20: 1Mentions · 2026-09-21: 309-2009-21
Referenced assets3 URLs
Full discourse4 posts
  • Dark Web Intelligence@DailyDarkWeb

    🚨 CRITICAL REDCAP RCE DISCLOSED — PUBLIC SURVEY CONTEXT CAN LEAD TO SERVER CODE EXECUTION A newly published vulnerability in Vanderbilt University's REDCap research-data platform allows remote code execution without authentication. • CVE-2026-90817 — CVSS 9.8 Critical • Published September 20, 2026 • The flaw affects REDCap's survey passthrough routing and Data Import processing logic • An attacker can manipulate HTTP requests to reach an unintended controller route and supply a crafted file-path/stream parameter • Successful exploitation can execute arbitrary code on the REDCap server • Authentication is NOT required • Exploitation does require knowledge of a valid public survey hash — notable because public survey links are designed to be distributed externally • The CVE record describes REDCap 13.3.0 and higher as affected; structured version data lists 16.0.49, 17.3.10 and 17.4.4 as unaffected releases • No public PoC or confirmed in-the-wild exploitation has been identified at this time ⚠️ Analyst Note: REDCap is used for research and clinical data collection, making server-side compromise potentially significant where deployments contain sensitive study or participant information. The attack prerequisite is also unusual: rather than requiring an account, the attacker needs a valid public survey hash. Organizations operating internet-facing REDCap deployments should verify their exact version and remediation status immediately. Original CVE record: https://www.cve.org/CVERecord?id=CVE-2026-90817 #REDCap #CVE202690817 #RCE #Vulnerability #HealthcareSecurity #CyberSecurity #ThreatIntel #DDW #DarkWeb

    000513.9K
    204.6K followersView on X
  • Cyber Threat Observatory | Alan Turing Institute@TuringCyberObs

    CVE-2026-90817 REDCap Unauthenticated RCE could expose clinical trial, patient-linked and research data in affected REDCap survey deployments Full analysis: https://github.com/alan-turing-institute/cyber-threat-observatory/blob/main/reports/2026-09-20/TIER_2_CVE-2026-90817.md #CyberSecurity #HealthcareCybersecurity #VulnerabilityManagement

    0101155
    62 followersView on X
  • mürrez@murrezsec

    CVE-2026-90817 — REDCap unauth RCE (CVSS 9.8) Survey __passthru + Data Import. Public survey hash (s=) required. Python mass checker + __passthru probes. Full exploit chain not public yet. Patch: 16.0.49 / 17.3.10 / 17.4.4 https://github.com/murrez/CVE-2026-90817 #REDCap #InfoSec #cve #poc

    0002057
    601 followersView on X
  • CVE@CVEnew

    CVE-2026-90817 An unauthenticated Remote Code Execution vulnerability was found in the survey passthrough routing and Data Import processing logic, in which a malicious user could p… https://www.cve.org/CVERecord?id=CVE-2026-90817

    00000946
    58.1K followersView on X

Explore more