Junglewise Threat Intelligence

CVE-2026-90817: REDCap remote code execution in survey and data import

CVE-2026-90817 · Severity: critical · CVSS 9.8 · Published 2026-09-20

Executive brief

REDCap is a secure data capture platform used by research institutions to manage clinical trial data and surveys. An unauthenticated attacker can execute arbitrary code on REDCap servers by manipulating public survey requests and file import parameters, potentially leading to full server compromise, data theft, or system manipulation. The attacker only needs knowledge of a public survey identifier, making the risk significant for any organization using REDCap.

Technical details

The vulnerability exists in survey passthrough routing and data import processing logic, allowing unauthenticated remote code execution through HTTP request manipulation and crafted file-path/stream parameters. An attacker with knowledge of a valid public survey hash can access unintended controller routes and supply malicious payloads during import handling, achieving code execution on the server. This affects REDCap 13.3.0 and later versions.

Affected products

  • Vanderbilt University REDCap 13.3.0 and higher

Timeline

  • 2026-09-20: disclosed

References