PatchSiren

Vanderbilt University CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

CRITICAL Vanderbilt University CVE published 2026-09-20

CVE-2026-90817

A critical vulnerability was found in REDCap 13.3.0 and higher, allowing unauthenticated remote code execution through survey passthrough routing and Data Import processing logic. Exploitation requires knowledge of a valid public survey hash but no authentication. This vulnerability exists in REDCap 13.3.0 and higher, potentially allowing attackers to execute arbitrary code. REDCap server administrators a [truncated]