CVE-CVE-2026-90817
Severity
CRITICAL
CVSS Score
9.8
Description
An unauthenticated Remote Code Execution vulnerability was found in the survey passthrough routing and Data Import processing logic, in which a malicious user could potentially exploit it by manipulating HTTP requests to access an unintended controller route from a public survey context and by supplying a crafted file-path/stream parameter during import handling. If successfully exploited, this could allow the attacker to remotely execute arbitrary code on the REDCap server. The attacker does no...
PoCs for CVE-CVE-2026-90817
CVE-2026-90817
RCE
Python
1
murrez
2026-09-21