PatchSiren cyber security CVE debrief
CVE-2026-100846 Project-MONAI CVE debrief
MONAI before 1.5.2 contains a deserialization of untrusted data vulnerability in the algo_from_pickle function in monai/auto3dseg/utils.py. The function reads a .pkl file and passes its contents to pickle.loads without validating the data source or content. If an application invokes algo_from_pickle on an attacker-supplied pickle file, an object defining __reduce__ is executed during deserialization, resulting in arbitrary code execution in the context of the application.
- Vendor
- Project-MONAI
- Product
- MONAI
- CVSS
- HIGH 8.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-27
- Original CVE updated
- 2026-10-08
- Advisory published
- 2026-09-27
- Advisory updated
- 2026-10-08
Who should care
Defenders responsible for MONAI deployments, security teams, and vulnerability management teams should assess exposure and prioritize verification and remediation. Operators of affected platforms and those responsible for securing MONAI applications should also take note of this vulnerability and plan for necessary updates or mitigations.
Why it matters
Defenders should care about CVE-2026-100846 because it allows for arbitrary code execution in MONAI applications via deserialization of untrusted data. Relevant roles include those responsible for MONAI deployments, who should assess exposure and prioritize verification and remediation. The vulnerability supports potential operational impacts, including the need for verification of MONAI versions and exposure, and priority for restricting access to pickle files and implementing input validation.
- Potential for arbitrary code execution in MONAI applications
- Need for verification of MONAI versions and exposure
- Priority for restricting access to pickle files and implementing input validation
Technical summary
The algo_from_pickle function in monai/auto3dseg/utils.py deserializes untrusted data from .pkl files without validation, allowing for arbitrary code execution in the context of the application. This vulnerability affects MONAI versions before 1.5.2 and can be exploited if an application invokes algo_from_pickle on an attacker-supplied pickle file. The deserialization process executes an object defining __reduce__, leading to potential code execution. Defenders should prioritize verifying MONAI versions and restricting access to pickle files.
Defensive priority
Defenders should prioritize verifying MONAI versions and restricting access to pickle files.
Recommended defensive actions
- Verify MONAI version and upgrade to 1.5.2 or later
- Restrict access to pickle files
- Implement input validation and sanitization
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
Evidence notes
The CVE record and source item provide details about the vulnerability in MONAI before 1.5.2. The NVD entry is currently UNVERIFIED. Defenders should verify MONAI versions, assess exposure, and prioritize remediation based on the provided information. The vulnerability allows for arbitrary code execution via deserialization of untrusted data in .pkl files.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-100846 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-100846
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-100846 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-100846
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
MONAI before 1.5.2 Remote Code Execution via Pickle Deserialization
Unverified legacy reference
URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/100xxx/CVE-2026-100846.json
cve_program_cvelist_v5
-
Source reference
Unverified legacy reference
URL: https://github.com/Project-MONAI/MONAI/security/advisories/GHSA-89gg-p5r5-q6r4
Supplemental source - vendor-advisory
-
Source reference
Unverified legacy reference
URL: https://www.vulncheck.com/advisories/monai-before-1.5.2-remote-code-execution-via-pickle-deserialization
Supplemental source - third-party-advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.