PT-2026-95962 · Redcap · Redcap

·

CVE-2026-90817

·

Published

2026-09-20

·

Updated

2026-10-02

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions REDCap versions 13.3.0 through 16.0.48 REDCap versions 17.0.0 through 17.3.9 REDCap versions 17.4.0 through 17.4.3
Description An unauthenticated remote code execution flaw exists in the survey passthrough routing and Data Import processing logic. A malicious actor can manipulate HTTP requests to access an unintended controller route from a public survey context and provide a crafted file-path/stream parameter during import handling. Successful exploitation allows the execution of arbitrary code on the server. This attack does not require authentication but requires knowledge of a valid public survey hash.
Recommendations Update to version 16.0.49, 17.3.10, or 17.4.4.

Fix

RCE

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-90817

Affected Products

Redcap