CRITICAL 9.8 CVE-2026-90817 Published 20 Sept 2026

REDCap Survey Routing Remote Code Execution Vulnerability

Worried this affects your website?

An unauthenticated Remote Code Execution vulnerability exists in REDCap, caused by flawed survey passthrough routing and Data Import processing logic.

An attacker can exploit it by manipulating HTTP requests to access an unintended controller route from a public survey context, and by supplying a crafted file-path/stream parameter during import handling.

Successful exploitation allows arbitrary code execution on the REDCap server.

  • No authentication is required.
  • Exploitation requires knowledge of a valid public survey hash.
  • Affected versions: REDCap 13.3.0 and higher.

Reference: CVE-2026-90817 on NVD

← Back to Security News