Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
Upgrade to REDCap 16.0.49 LTS, 17.3.10 LTS, or 17.4.4 Standard Release, as applicable.
Tracking
Sign in to view the affected projects.
No advisories yet.
| Link | Providers |
|---|---|
| https://www.securifera.com/advisories/ |
|
Sun, 20 Sep 2026 14:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Remote Code Execution via Survey Passthrough Routing and Data Import in REDCap |
Sun, 20 Sep 2026 12:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An unauthenticated Remote Code Execution vulnerability was found in the survey passthrough routing and Data Import processing logic, in which a malicious user could potentially exploit it by manipulating HTTP requests to access an unintended controller route from a public survey context and by supplying a crafted file-path/stream parameter during import handling. If successfully exploited, this could allow the attacker to remotely execute arbitrary code on the REDCap server. The attacker does not have to be authenticated in order to exploit this, but exploitation requires knowledge of a valid public survey hash. This vulnerability exists in REDCap 13.3.0 and higher. | |
| Weaknesses | CWE-73 CWE-94 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: Securifera
Published:
Updated: 2026-09-20T12:05:32.698Z
Reserved: 2026-09-13T17:35:41.413Z
Link: CVE-2026-90817
No data.
Status : Received
Published: 2026-09-20T13:17:44.973
Modified: 2026-09-20T13:17:44.973
Link: CVE-2026-90817
No data.
OpenCVE Enrichment
Updated: 2026-09-20T13:45:07Z
