Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.8
CVE-2026-90817: REDCap allows remote code execution via public survey
CVE-2026-90817 · published 8 days ago
Summary
The REDCap system (version 13.3.0 and later) can be tricked into running any code an attacker provides, without needing a login, by sending specially crafted requests to a public survey link. This could let an attacker take control of the REDCap server. Apply the vendor's patch or upgrade to a fixed version as soon as possible.
What to do
The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| vanderbilt university | redcap | 13.3.0 |
Original advisory text
An unauthenticated Remote Code Execution vulnerability was found in the survey passthrough routing and Data Import processing logic, in which a malicious user could potentially exploit it by manipu...
An unauthenticated Remote Code Execution vulnerability was found in the survey passthrough routing and Data Import processing logic, in which a malicious user could potentially exploit it by manipulating HTTP requests to access an unintended controller route from a public survey context and by supplying a crafted file-path/stream parameter during import handling. If successfully exploited, this could allow the attacker to remotely execute arbitrary code on the REDCap server. The attacker does not have to be authenticated in order to exploit this, but exploitation requires knowledge of a valid public survey hash. This vulnerability exists in REDCap 13.3.0 and higher.
References
Severity
9.8
Critical
CVSS 3.1: 9.8 (NVD)
Exploitation
EPSS <1%
Type
CWE-73External Control of File Name or Path
CWE-94Code Injection
Timeline
Published20 Sep 2026
Updated27 Sep 2026
First seen20 Sep 2026
Track software like this
Free during beta