{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3avanderbiltredcap/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:vanderbilt:redcap:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":9.8,"id":"CVE-2026-90817"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["REDCap (\u003e= 13.3.0)"],"_cs_severities":["critical"],"_cs_tags":["cve-2026-90817","remote-code-execution","vulnerability","webserver"],"_cs_type":"advisory","_cs_vendors":["Vanderbilt"],"content_html":"\u003cp\u003eCVE-2026-90817 is a critical remote code execution (RCE) vulnerability affecting Vanderbilt REDCap versions 13.3.0 and later. The vulnerability stems from an insecure implementation of the survey passthrough ('__passthru') routing mechanism. By manipulating this parameter within a public survey context, an unauthenticated attacker can force the application to route requests to restricted internal controllers, specifically the Data Import module. This improper routing, combined with insecure file-path or stream handling, allows for the execution of arbitrary code on the underlying web server. While the vulnerability requires a valid public survey hash ('s=') to trigger the full chain, the widespread use of public-facing surveys in academic and clinical research environments significantly increases the attack surface. Organizations using REDCap are strongly urged to patch to the identified LTS or standard releases immediately.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe vulnerability carries a CVSS score of 9.8, indicating high potential for full system compromise. If exploited, attackers can gain unauthorized remote code execution, leading to data exfiltration of sensitive research and patient information, lateral movement within the hosting network, and loss of integrity for the affected REDCap research databases. The vulnerability impacts numerous academic, research, and healthcare institutions that rely on REDCap for data collection.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade all affected REDCap instances to the patched versions: 16.0.49 LTS, 17.3.10 LTS, or 17.4.4 Standard, as specified by the vendor.\u003c/li\u003e\n\u003cli\u003eDeploy the Sigma rules provided in this brief to detect scanning and exploitation attempts targeting the '__passthru' parameter.\u003c/li\u003e\n\u003cli\u003eMonitor web server logs for suspicious HTTP requests containing '__passthru' directed at administrative or data import URI stems.\u003c/li\u003e\n\u003cli\u003eRestrict public access to survey endpoints and implement WAF rules to sanitize or block requests containing unusual path traversal or controller manipulation strings.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-24T10:11:59Z","date_published":"2026-09-24T10:11:59Z","id":"https://feed.craftedsignal.io/briefs/2026-09-redcap-rce/","summary":"A critical unauthenticated RCE vulnerability (CVE-2026-90817) in Vanderbilt REDCap allows attackers to bypass routing restrictions through the '__passthru' parameter, enabling unauthorized access to administrative controllers.","title":"Critical Remote Code Execution in Vanderbilt REDCap via Survey Passthru","url":"https://feed.craftedsignal.io/briefs/2026-09-redcap-rce/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:vanderbilt:redcap:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}