OCTOBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-90817

CRITICAL · CVSS 9.8 EPSS 0.88% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-20 · Last synced 2026-10-07

CyberRota Analysis

AI-Generated

REDCap versions 13.3.0 and higher are vulnerable to an unauthenticated Remote Code Execution flaw that allows attackers to manipulate HTTP requests and access unintended controller routes through public survey contexts. Successful exploitation could enable remote execution of arbitrary code on the server, posing a critical risk to data integrity and system security. Organizations using REDCap should prioritize immediate patching or mitigation strategies to safeguard against potential exploitation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit remote code execution code execution

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-90817
Severity
CRITICAL
CVSS
9.8
EPSS
0.88%

Original NVD Description

An unauthenticated Remote Code Execution vulnerability was found in the survey passthrough routing and Data Import processing logic, in which a malicious user could potentially exploit it by manipulating HTTP requests to access an unintended controller route from a public survey context and by supplying a crafted file-path/stream parameter during import handling. If successfully exploited, this could allow the attacker to remotely execute arbitrary code on the REDCap server. The attacker does not have to be authenticated in order to exploit this, but exploitation requires knowledge of a valid public survey hash. This vulnerability exists in REDCap 13.3.0 and higher.