Vulnerability Report

CVE-2026-90817

RCE

Title: Unauthenticated Remote Code Execution in REDCap

Arbitrary File Access

Proof Of Concept

PoC Available for CVE-2026-90817

CWE Category CWE-73
Published Date Sep 20, 2026
Modified Date Sep 22, 2026
Exploit Status Available
Score 9.8 CVSS v3.1
Exploit Probability (EPSS)
0.95%

Vulnerability Summary

CVE-2026-90817: An unauthenticated Remote Code Execution vulnerability was found in the survey passthrough routing and Data Import processing logic, in which a malicious user could potentially exploit it by manipulating HTTP requests to access an unintended controller route from a public survey context and by supplying a crafted file-path/stream parameter during import handling. If successfully exploited, this could allow the attacker to remotely execute arbitrary code on the REDCap server. The attacker does not have to be authenticated in order to exploit this, but exploitation requires knowledge of a valid public survey hash. This vulnerability exists in REDCap 13.3.0 and higher.

Impacted Vendors

Analysis in Progress...

Reference Links

CVSS v3.1
Source Entity [email protected]
Severity CRITICAL
9.8
Attack Vector
NETWORK
Complexity
LOW
Privileges
N/A
Interaction
NONE
Confidentiality
N/A
Integrity
N/A
Availability
N/A
Scope
UNCHANGED
RAW VECTOR CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Associated Attack Patterns (CAPEC)

Total: Patterns

CVE-2026-90817 Exploits & PoCs (Proof Of Concept)

GitHub https://github.com/murrez/CVE-2026-90817
View Code
GitHub https://github.com/ExDev994/CVE-2026-90817
View Code
GitHub https://github.com/yulisec/CVE-2026-90817
View Code
GitHub https://github.com/Farih123/CVE-2026-90817
View Code
MODIFIED

Vulnerability data updated via NVD.

MODIFIED

Vulnerability data updated via NVD.

MODIFIED

Vulnerability data updated via NVD.

Attack Vector Matrix

Access Vector NETWORK
Complexity LOW
Privileges N/A
Interaction NONE
CVSS Vector String CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected Stack

No specific products linked.