PT-2026-95962 · Redcap · Redcap
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
REDCap versions 13.3.0 through 16.0.48
REDCap versions 17.0.0 through 17.3.9
REDCap versions 17.4.0 through 17.4.3
Description
An unauthenticated remote code execution flaw exists in the survey passthrough routing and Data Import processing logic. A malicious actor can manipulate HTTP requests to access an unintended controller route from a public survey context and provide a crafted file-path/stream parameter during import handling. Successful exploitation allows the execution of arbitrary code on the server. This attack does not require authentication but requires knowledge of a valid public survey hash.
Recommendations
Update to version 16.0.49, 17.3.10, or 17.4.4.
Fix
RCE
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Redcap