Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-90817

Quick assessment

Affected
Vanderbilt University REDCap
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

在 REDCap 13.3.0 及更高版本中,发现了一个未认证远程代码执行(RCE)漏洞。该漏洞存在于调查(Survey)直通路由及数据导入处理逻辑中。恶意用户可通过操纵 HTTP 请求,从公共调查上下文访问本不应被允许的控制器路由,并在导入处理过程中提供经过构造的文件路径/流参数来利用该漏洞。若成功利用,攻击者可在 REDCap 服务器上远程执行任意代码。攻击者无需经过身份验证即可尝试利用此漏洞,但利用的前提是必须知晓一个有效的公共调查哈希值(public survey hash)。

CVSS 9.8 · Critical
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-90817

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: CVE Program / CVE List V5
Vulnerability Description
An unauthenticated Remote Code Execution vulnerability was found in the survey passthrough routing and Data Import processing logic, in which a malicious user could potentially exploit it by manipulating HTTP requests to access an unintended controller route from a public survey context and by supplying a crafted file-path/stream parameter during import handling. If successfully exploited, this could allow the attacker to remotely execute arbitrary code on the REDCap server. The attacker does not have to be authenticated in order to exploit this, but exploitation requires knowledge of a valid public survey hash. This vulnerability exists in REDCap 13.3.0 and higher.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
对生成代码的控制不恰当(代码注入)
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Vanderbilt University REDCap 13.3.0 -

II. Public POCs for CVE-2026-90817

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-90817

登录查看更多情报信息。

IV. Related Vulnerabilities

V. Comments for CVE-2026-90817

No comments yet


Leave a comment