OCTOBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-100840

HIGH · CVSS 7.8 EPSS 0.21% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-27 · Last synced 2026-10-07

CyberRota Analysis

AI-Generated

The vulnerability in MONAI allows remote code execution due to improper handling of bundle configuration, enabling attackers to craft malicious bundles that execute arbitrary code when loaded by victims. This poses a significant risk to any users of MONAI versions up to 1.6.0, particularly in environments where untrusted bundles may be loaded. Organizations utilizing MONAI for medical imaging or related applications should prioritize patching to mitigate potential exploitation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
remote code execution code execution
GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-100840
Severity
HIGH
CVSS
7.8
EPSS
0.21%

Original NVD Description

MONAI through 1.6.0 contains a remote code execution vulnerability in the bundle configuration engine that resolves _target_ values to arbitrary importable callables without an allow list and passes $ expressions to Python eval(). Attackers can publish a malicious bundle with crafted configuration containing arbitrary code that executes when a victim loads the bundle using monai.bundle.load() or monai.bundle.run().

Related CVEs

Other vulnerabilities affecting the same vendor(s)