CVE-2026-90817

9.8

Vanderbilt University · REDCap

A critical remote code execution vulnerability exists in REDCap survey routing and data import logic, allowing unauthenticated attackers to execute arbitrary code via manipulated HTTP requests.

Executive summary

An unauthenticated remote code execution vulnerability in Vanderbilt University REDCap poses a critical risk to server integrity and data confidentiality.

Vulnerability

The flaw involves improper control of code generation and external control of file paths within the survey passthrough routing and data import processing logic. An unauthenticated attacker can trigger code execution by submitting crafted HTTP requests containing a valid public survey hash.

Business impact

A successful exploit grants an attacker full remote code execution capabilities on the underlying REDCap server. Given the CVSS score of 9.8, this vulnerability represents a critical threat that could lead to complete system compromise, unauthorized access to sensitive research data, and potential lateral movement within the hosting network.

Remediation

Immediate Action: Upgrade to REDCap 16.0.49 LTS, 17.3.10 LTS, or 17.4.4 Standard Release, depending on the specific deployment branch, to apply the necessary security patches.

Proactive Monitoring: Monitor server access logs for anomalous controller route requests and unusual file path or stream parameters associated with public survey traffic.

Compensating Controls: Implement strict Web Application Firewall (WAF) rules to filter and block suspicious HTTP requests targeting survey routing parameters or file import streams until patching is complete.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

This vulnerability is critical due to the potential for unauthenticated remote code execution. Administrators should prioritize the immediate application of the provided security updates to the specified LTS or standard versions. Failure to patch these systems leaves the server exposed to full compromise by any actor with access to a public survey hash.

More Vanderbilt University CVEs

History

  1. Disclosed CVE record published
  2. Collected by CVE Brief via github
  3. Analyst report written
  4. Published in the daily brief critical section

Sources

Originally found and disclosed by Ryan Wincey (@rwincey, Securifera), per the CVE Program record.