Dataminr INTEL BRIEF

CVE-2026-90817 (REDCap Unauthenticated RCE)

A newly disclosed vulnerability (CVSS ~9.8) lets attackers execute arbitrary code on REDCap servers with no authentication — just a public survey link. With a working exploit already public and REDCap widely deployed across research hospitals and universities, patching isn't optional this week. Here's what security teams need to know and do right now.

CVE-2026-90817 (REDCap Unauthenticated RCE)
DATE September 21, 2026
AUTHOR Dataminr Threat Research & Cyber Engineering
SHARE
  • Subscribe via RSS
CYBER DEFENSE

Key Takeaways

  • Critical Unauthenticated RCE: CVE-2026-90817 lets an attacker execute arbitrary code on a REDCap server, CVSS approximately 9.8, no authentication required.
  • Broad Version Exposure: Affects REDCap 13.3.0 and higher, with no upper bound named in the advisory.
  • Two-Stage Attack Chain: Exploitation requires a valid public survey hash, then abuses survey passthrough routing plus a crafted Data Import parameter.
  • Public Exploit Now Available: A working proof-of-concept has been published, demonstrating successful remote code execution. This should be treated as actively exploitable.
  • Patch Confirmed: Fixed in REDCap 16.0.49 LTS, 17.3.10 LTS, and 17.4.4 Standard Release.

Executive Summary

Vanderbilt’s REDCap research-data platform — widely deployed across academic medical centers, hospitals, public health agencies, and grant-funded research programs — contains a critical, unauthenticated remote code execution vulnerability (CVE-2026-90817, CVSS approximately 9.8) disclosed September 20, 2026. An external attacker requires no credentials to compromise an affected server; the only prerequisite is a publicly accessible survey link (hash), information that is frequently shared openly or indexed as part of normal research operations.

Exploitation occurs via a two-stage attack chain: an attacker leverages a valid public survey hash to abuse REDCap’s survey passthrough routing (__passthru) to reach an unintended controller, then supplies a crafted file-path or stream parameter during Data Import processing to execute arbitrary code in the context of the web server process (e.g., www-data). A working public proof-of-concept (ExDev994/CVE-2026-90817) is now available, significantly increasing the likelihood of opportunistic mass-scanning and attack activity against internet-facing instances.

Organizations operating REDCap should treat this as an urgent risk item rather than a routine patch-cycle matter, for three key reasons:

  • Protected Health Information Exposure: Affected instances commonly store participant PHI/PII and human-subjects research data, creating immediate HIPAA, IRB, and regulatory breach-notification risks upon compromise.
  • Network Foothold & Lateral Movement: REDCap servers are frequently integrated with institutional SSO, file storage, and EHR-adjacent systems, allowing a single compromised host to serve as an initial access foothold into a broader research or hospital network.
  • Active Exploitation Risk: The availability of confirmed, working exploit code drastically narrows the window before widespread malicious targeting.

Patches are available in REDCap 16.0.49 LTS, 17.3.10 LTS, and 17.4.4 Standard Release. Affected stakeholders should direct IT and security teams to verify the patch status of all REDCap deployments today, audit department- or lab-run instances operating outside central management, and confirm incident-response protocols are prepared.

Immediate Actions & Recommendations

Confirm your REDCap version against 13.3.0 and above; treat any instance in that range as potentially exposed until a fix is confirmed.

Check Vanderbilt’s official REDCap security advisory/consortium channel directly for the authoritative patched version — do not rely on third-party trackers alone for the fix version.

Audit whether any REDCap instance exposes public survey links; a valid survey hash is a precondition for this exploit, so restricting or auditing public survey exposure reduces risk even before patching.

Monitor for anomalous requests to Data Import / survey passthrough (__passthru) routes as a detection signal, since a public checker/fingerprinting tool for this CVE already exists.

Treat this as evolving: it was disclosed roughly one day before this brief, so official patch guidance and any working exploit code may change quickly.

2026 Mid-Year Threat Landscape Report

The first half of 2026 was defined by a widening gap between attack speed and defense speed — and AI is accelerating both sides. Dataminr’s 2026 Cyber Threat Landscape Mid-Year Report pulls from 4,500 threat actors tracked, 73,000 vulnerabilities detected, and over 2 million alerts processed per month to surface what actually mattered in H1 and what teams need to prepare for in H2.

Download Report
Sep 21, 2026

SHARE
  • Cyber Defense
  • Cyber Risk
  • Intel Brief