PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-100846 Project-MONAI CVE debrief

MONAI before 1.5.2 contains a deserialization of untrusted data vulnerability in the algo_from_pickle function in monai/auto3dseg/utils.py. The function reads a .pkl file and passes its contents to pickle.loads without validating the data source or content. If an application invokes algo_from_pickle on an attacker-supplied pickle file, an object defining __reduce__ is executed during deserialization, resulting in arbitrary code execution in the context of the application.

Vendor
Project-MONAI
Product
MONAI
CVSS
HIGH 8.8
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-27
Original CVE updated
2026-10-08
Advisory published
2026-09-27
Advisory updated
2026-10-08

Who should care

Defenders responsible for MONAI deployments, security teams, and vulnerability management teams should assess exposure and prioritize verification and remediation. Operators of affected platforms and those responsible for securing MONAI applications should also take note of this vulnerability and plan for necessary updates or mitigations.

Why it matters

Defenders should care about CVE-2026-100846 because it allows for arbitrary code execution in MONAI applications via deserialization of untrusted data. Relevant roles include those responsible for MONAI deployments, who should assess exposure and prioritize verification and remediation. The vulnerability supports potential operational impacts, including the need for verification of MONAI versions and exposure, and priority for restricting access to pickle files and implementing input validation.

  • Potential for arbitrary code execution in MONAI applications
  • Need for verification of MONAI versions and exposure
  • Priority for restricting access to pickle files and implementing input validation

Technical summary

The algo_from_pickle function in monai/auto3dseg/utils.py deserializes untrusted data from .pkl files without validation, allowing for arbitrary code execution in the context of the application. This vulnerability affects MONAI versions before 1.5.2 and can be exploited if an application invokes algo_from_pickle on an attacker-supplied pickle file. The deserialization process executes an object defining __reduce__, leading to potential code execution. Defenders should prioritize verifying MONAI versions and restricting access to pickle files.

Defensive priority

Defenders should prioritize verifying MONAI versions and restricting access to pickle files.

Recommended defensive actions

  • Verify MONAI version and upgrade to 1.5.2 or later
  • Restrict access to pickle files
  • Implement input validation and sanitization
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up

Evidence notes

The CVE record and source item provide details about the vulnerability in MONAI before 1.5.2. The NVD entry is currently UNVERIFIED. Defenders should verify MONAI versions, assess exposure, and prioritize remediation based on the provided information. The vulnerability allows for arbitrary code execution via deserialization of untrusted data in .pkl files.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-100846 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-100846

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-100846 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-100846

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • MONAI before 1.5.2 Remote Code Execution via Pickle Deserialization

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/100xxx/CVE-2026-100846.json

    cve_program_cvelist_v5

  • Source reference

    Unverified legacy reference

    URL: https://github.com/Project-MONAI/MONAI/security/advisories/GHSA-89gg-p5r5-q6r4

    Supplemental source - vendor-advisory

  • Source reference

    Unverified legacy reference

    URL: https://www.vulncheck.com/advisories/monai-before-1.5.2-remote-code-execution-via-pickle-deserialization

    Supplemental source - third-party-advisory

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.