PatchSiren cyber security CVE debrief
CVE-2026-90817 Vanderbilt University CVE debrief
A critical vulnerability was found in REDCap 13.3.0 and higher, allowing unauthenticated remote code execution through survey passthrough routing and Data Import processing logic. Exploitation requires knowledge of a valid public survey hash but no authentication. This vulnerability exists in REDCap 13.3.0 and higher, potentially allowing attackers to execute arbitrary code. REDCap server administrators and security teams should assess exposure and prioritize remediation to prevent potential exploitation.
- Vendor
- Vanderbilt University
- Product
- REDCap
- CVSS
- CRITICAL 9.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-20
- Original CVE updated
- 2026-09-20
- Advisory published
- 2026-09-20
- Advisory updated
- 2026-09-20
Who should care
REDCap server administrators, security teams, and IT personnel responsible for vulnerability management and patching should assess exposure and prioritize remediation. They should verify REDCap server exposure and public survey hashes, review server logs for suspicious import handling and HTTP requests, and implement compensating controls to restrict access to public survey contexts.
Why it matters
CVE-2026-90817 is a critical vulnerability in REDCap 13.3.0 and higher, allowing unauthenticated remote code execution. REDCap server administrators and security teams should assess exposure and prioritize remediation to prevent potential exploitation.
- Potential for unauthenticated remote code execution
- Possible exploitation through public survey contexts
- Need for validation of file-path/stream parameters during import
- Requirement for immediate verification of REDCap server exposure
Technical summary
The vulnerability exists in REDCap 13.3.0 and higher, allowing unauthenticated remote code execution through survey passthrough routing and Data Import processing logic. A malicious user could potentially exploit it by manipulating HTTP requests to access an unintended controller route from a public survey context and by supplying a crafted file-path/stream parameter during import handling. This could allow the attacker to remotely execute arbitrary code on the REDCap server. Exploitation requires knowledge of a valid public survey hash but no authentication.
Defensive priority
Immediate verification of REDCap server exposure and public survey hashes is required to assess potential vulnerability. Review server logs for suspicious import handling and HTTP requests. Implement compensating controls to restrict access to public survey contexts and validate file-path/stream parameters during import.
Recommended defensive actions
- Verify REDCap server exposure and public survey hashes
- Review server logs for suspicious import handling and HTTP requests
- Implement compensating controls to restrict access to public survey contexts
- Validate file-path/stream parameters during import
- Restrict access to REDCap server if possible
Evidence notes
The CVE record and NVD entry provide details on the vulnerability, including its critical CVSS score of 9.8 and potential for unauthenticated remote code execution. However, specific details about affected versions, exploitation, and remediation are limited.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-90817 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-90817
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-90817 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-90817
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://www.securifera.com/advisories/
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.