No advisories yet.
Solution
Upgrade to REDCap 16.0.49 LTS, 17.3.10 LTS, or 17.4.4 Standard Release, as applicable.
Workaround
No workaround given by the vendor.
| Link | Providers |
|---|---|
| https://www.securifera.com/advisories/ |
|
Mon, 21 Sep 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 21 Sep 2026 10:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Vanderbilt University
Vanderbilt University redcap |
|
| Vendors & Products |
Vanderbilt University
Vanderbilt University redcap |
Sun, 20 Sep 2026 14:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Remote Code Execution via Survey Passthrough Routing and Data Import in REDCap |
Sun, 20 Sep 2026 12:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An unauthenticated Remote Code Execution vulnerability was found in the survey passthrough routing and Data Import processing logic, in which a malicious user could potentially exploit it by manipulating HTTP requests to access an unintended controller route from a public survey context and by supplying a crafted file-path/stream parameter during import handling. If successfully exploited, this could allow the attacker to remotely execute arbitrary code on the REDCap server. The attacker does not have to be authenticated in order to exploit this, but exploitation requires knowledge of a valid public survey hash. This vulnerability exists in REDCap 13.3.0 and higher. | |
| Weaknesses | CWE-73 CWE-94 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Securifera
Published:
Updated: 2026-09-21T14:16:08.677Z
Reserved: 2026-09-13T17:35:41.413Z
Link: CVE-2026-90817
Updated: 2026-09-21T14:16:02.970Z
Status : Awaiting Analysis
Published: 2026-09-20T13:17:44.973
Modified: 2026-09-22T19:44:01.280
Link: CVE-2026-90817
No data.
OpenCVE Enrichment
Updated: 2026-09-21T10:02:31Z